Hacker News new | past | comments | ask | show | jobs | submit login

Normal people don’t usually run password generation algorithms in their heads. When they do, the algorithm sucks. This is why we have password managers in the first place.



The formula can be very simple and is applied to less important services.

Unless you are directly, personally, targeted no hacker will waste the time trying to reverse engineer your algorithm... they'll just go on to brute forcing the next hash in the list.

And most people only have a few services that need to be truly secure anyway, which would use non-derived passwords (if they hack your netflix or spotify, who cares? Call support and get it back)

Password managers have had many exploits/failures over the years. You introduce so many points of failures bringing in a third party.

Your gibberish password with random symbols/characters isn't any more secure than a more memorable one of a similar length.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: