Comment on I have an acquaintance that have their own "password system" that involves having a "core" set of characters, plus a few unique characters for each site; Is that system safe?

F04118F@feddit.nl ⁨4⁩ ⁨days⁩ ago

There’s literally only 4 characters difference between all their passwords, even if those would be completely random, that’s very bad.

They don’t seem to understand that it’s not about how many samples you need to see to be sure what their Amazon password is. The problem is that if one of their passwords ever leaks, some bot can brute-force try thousands of variations on it and find any other password very quickly (they effectively only have to guess 4 characters, plus a bit to find that it’s the first 4 to change).

How can anyone think this is more secure than having completely different and long passwords for every site?

They probably don’t understand that your pw manager’s password is safer because you don’t enter it anywhere, only into your password manager (ideally with 2FA). This person is effectively spreading their master password around by putting it as the core of ALL their passwords, significantly increasing the risk that it leaks.

source
Sort:hotnewtop