Disclaimer: I use a password manager, so please don’t direct your comments at me.


So I know this person that says they don’t use a password manager because they have a better system like… I’m gonna give an example:

Lets say, a person loves Star Wars, and their favorite character is Yoda. The favorite Their favorite phrase is from The Good Place “This is the Bad Place!”. And their favorite date is 1969 July 20th (first landing on moon).

So here:

Star Wars Yoda = SWYd

“This is the Bad Place!” = ThIThBaPl!

1969 July 20 —> 69 07 20

So they have this “core” password = SWydThIThBaPl!690720

Then for each website, they add the website’s first and last 2 characters of the name to the front of the password…

So, “Lemmy Forum” = leum

Add this to the beginning of the “core” password it becomes:

leumSWydThIThBaPl!690720

For Protomail Email it’s: prilSWydThIThBaPl!690720

For Amazon Shopping it’s: amngSWydThIThBaPl!690720

Get the idea?

The person says that, since the beginning of the password is unique, its “unhackable”, and that the attacker would need like 3 samples of the password to figure out their system.

Is this person’s “password system” actually secure?

  • FriendOfDeSoto@startrek.website
    link
    fedilink
    English
    arrow-up
    2
    ·
    edit-2
    2 days ago

    I would say this system is safe until one password - through no fault of their own - gets leaked. Worse even, two of them. If a bored hacker sees them in a stolen list, they could go to town on all other accounts. So you should advise your acquaintance to change their system. Long passwords are great but if they repeat a lot of characters they are immediately less useful. If the repeating string is known it makes brute-forcing other accounts that much easier.

    The best advice is to keep unique passwords for all accounts. And by unique I mean not following a system like that. Long, random, non-sensical crap is best (but also most annoying) - for now. Once quantum computers become a thing, all this probably won’t matter any more.

    Edit: And always with non-SMS, non-emailed 2FA. But if those are the only options available it’s better than nothing.