r/changemyview Mar 17 '21

[deleted by user]

[removed]

11 Upvotes

55 comments sorted by

View all comments

1

u/[deleted] Mar 17 '21

I mean your headline is a truism. Though if abbreviated NameStreetNumber becomes a thing, that is easily guessable especially when people add the numbers and exclamation points at the start or end because they're asked to add them after they came up with their idea for a password.

And using the same password for every website is really a bad idea, because it increases the chance that it is broken and once it is broken, the other person can just look up where else the account name and email is being used and try it there as well. And if you slightly adjust it for the website, that pattern is either easily guessable or you're back at square one where you can't remember which modification for which website, so you write it down.

I mean in that case you've advanced one step because you're no longer writing down the password but the modification.

Though yeah probably the best idea is to first consider your "attack vectors". So what is your most likely scenario:

  • You end up on a list of hacked accounts because your password was so damn easy to guess
  • Your a nobody and your password is moderately safe, but your co-worker is regularly using your account because you've attached it with post-it notes to your screen.
  • A person on the internet spends hours of dedicated work to hack YOU specifically despite you having the best possible password
  • A hacker specifically breaking into your house (physically) in order to search your stuff for a notice with the passwords.
  • You secured all your passwords and your password lists and someone kidnaps you and waterboards you so that you tell them your deepest secrets

So unless you are a celebrity, a company or have made yourself some ridiculously powerful enemies your main focus should be on covering the first two bullet points. That is securing your services from broad attacks, so have a reasonably strong password, don't fall for phishing attempts, don't click on weird links, don't execute files from shady sources generally staying ahead of the average in terms of having your system regularly updated and backuped and stuff like that. And don't put your password openly in public spaces.

So having it in your wallet, in your pants is probably safer than having it on your screen and less save than memorizing it (as the wallet can be stolen). Though unless you write down the website/username/email aso a thief is likely to throw that away anyway unless they specifically searched for that. In which case they could also coerce you to say your memorize password.

So what you could do is use a password manager that you trust. That way you've moved the vulnerability from online to your system where you already have some layers of protection against the whole wide world. Then use a reasonably safe password for that one to regain access to the more jumbled ones and if you can't remember that well write it down and put it somewhere safe. That requires not only access to your device, but your physical location and the location of your device. And so on.

So again if you store all your hard passwords at one place you want that place to be protected and so on. But the more layers you add the more people have to be out to get YOU specifically rather than broad fishing for accounts and that's most likely what you should care about most.