Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Yeah I mean, there may be a goldilocks zone of sophisticated enough to remember 30 random strings of text but not sophisticated enough to need to remember 300 random strings of text, and yeah if it works for you that's awesome (I keep thinking I'll try and get my memory back to where it was when I was in college, but I keep forgetting to do it!! :P)

And yeah I think the big bad we're working against is people using the same password (or a password with some very small variations that's super easy to guess from a variant) across all their services. I'm sure almost everyone does this, I even know sophisticated engineers who do it, I also do it for accounts I don't care about. "Use a password manager browser extension" is the easiest thing for us former help deskers to tell people, and as long as that person didn't choose LastPass (which you should never have chosen, how many breaches will it take) they'll be in great shape.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: