Shit, just looking at the replies, there's a solid case for password managers. No normal human is going to memorize 100+ unique passwords meeting various complexity requirements. It almost makes shaming people for re-using passwords look like you're out of touch. Of course they're following bad practices, how could they not be?!
This. And password managers can do more by constantly checking latest account breaches like on https://haveibeenpwned.com then flagging it to their customers to rotate their credentials.
There's an unfortunate correlation between how long and complex my password is and how I often I have to manually type it in. Microsoft are really good in this regard, and you almost never have to type in your password once you have the Authenticator set up. Google isn't too bad, once you're logged in, but you still sometimes have to type out your password in a situation where having access to your password manager is not convenient. But I find Apple is the worst - I often need to type in my password, and often in situations where I don't have access to my password manager.
This. This is the only thing that actually solves all warts of authentication nowadays. Companies really should switch to a webauthn-first mindset. The technology has been here for over a decade, it's not new. There is a standrad and a library for every language, it's not hard. FIDO2 keys start at 20 bucks and every android phone can act as one, it's not expensive. They are literally the only thing that can actually protect you from phishing and they generate new login creds per domain, protecting your privacy. Companies, support webauthn!
I find those keys immensely inconvenient, though. I used them for a couple of years, but finally gave up and went back to long, randomly-generated passwords.
Yep. Password managers are quickly becoming a required utility for modern services. And oh how painful it would be to lose that. I memorize maybe 10~20 passwords. And I sometimes mix them up in my head as I type them too.
It's why we always laugh at anyone who says to "not reuse passwords".
I take a pragmatic approach: the dozen logins in my life that actually matter get strong unique passwords, and everything I don't give a shit about gets the same password.
Sooner or later someone could take control of one of the accounts you don't care about and use in a way you don't expect to gain control of things you do care about.
> use in a way you don't expect to gain control of things you do care about
An example would really drive your point home. Can you provide one that people would deem "dangerous"?
Edit: ccooffee just mentioned in the thread that you could be de-anonymized by reusing the same password. Is this what you mean? There's a spectrum of comfort with privacy so maybe that's the source of the disagreement between whether it is important to have unique passwords or not for accounts that don't contain financial/SSN/medical/etc information
Beyond my accounts related to my important email addresses, Steam, finances and medical which can all be counted on one or two hands, I really couldn't give a damn about the other accounts or their password security.
Strong and unique passwords for the important accounts, simple and reused passwords for the rest. You're welcome to hack into my accounts on Hacker News, Reddit, Discord, LINE, various IRC networks, various forums, etc. I don't care; there's nothing important in there besides sentimental value.
On its own, the information in those private accounts is probably not interesting. I used to use the "few sites get a unique and secret password, but most reuse the same 10 character one" ruleset, but I became worried about how much data could be aggregated about me. By re-using the same password, I felt like I gave a simple test that attackers could use to definitively confirm "user XYZ on site ABC is the same as ccooffee".
I'm now firmly in the "everything gets a unique password" camp. There are 4 important passwords I type myself, but everything else is in a password vault.
I take the same approach with the extra precaution that those logins also get a separate email address (with a different pseudo-strong password). Makes it really easy to share nonsense logins with my wife/family.