Disclaimer: I use a password manager, so please don’t direct your comments at me.


So I know this person that says they don’t use a password manager because they have a better system like… I’m gonna give an example:

Lets say, a person loves Star Wars, and their favorite character is Yoda. The favorite Their favorite phrase is from The Good Place “This is the Bad Place!”. And their favorite date is 1969 July 20th (first landing on moon).

So here:

Star Wars Yoda = SWYd

“This is the Bad Place!” = ThIThBaPl!

1969 July 20 —> 69 07 20

So they have this “core” password = SWydThIThBaPl!690720

Then for each website, they add the website’s first and last 2 characters of the name to the front of the password…

So, “Lemmy Forum” = leum

Add this to the beginning of the “core” password it becomes:

leumSWydThIThBaPl!690720

For Protomail Email it’s: prilSWydThIThBaPl!690720

For Amazon Shopping it’s: amngSWydThIThBaPl!690720

Get the idea?

The person says that, since the beginning of the password is unique, its “unhackable”, and that the attacker would need like 3 samples of the password to figure out their system.

Is this person’s “password system” actually secure?

  • null_dot@lemmy.dbzer0.com
    link
    fedilink
    English
    arrow-up
    13
    ·
    3 days ago

    I reject the premise!

    There is no safe or unsafe. It’s more like “more safe for a given person”.

    Your friend’s system is better than using the same password everywhere. It’s more difficult to hack than the majority of passwords that aren’t generated by password managers. If that’s what your friend likes and works for them well, fine I guess.

    It wouldn’t work for me because:

    • it doesn’t input the password for you. Does your friend really type passwords in all the time?
    • IDK if my memory is particularly bad but having to remember anything at all is hit and miss. Like I could remember those characters that are used everywhere, but for the router at my mum and dads house that I haven’t accessed in 5 years, was it “mums router” or “router mums house
    • Also I manage multiple passwords for the same sites, as in credentials for my partner or whatever, but I guess I could make variant of this system.
    • also if I were to die the person who sorts out all my stuff will have access to my passwords
    • but the main reason is… I use my keepassxc db as a database for all sorts of things which aren’t necessarily passwords. ssh keys are a good example. I use it for TOTP. bank card details. membership numbers and government ids. VIN numbers for vehicles. Also, a weird one, I have to keep track of about 100 physical keys for reasons, I stamp a number on them like k32 and then store that number and an explanation of what it’s for in my db.