You are viewing a single comment's thread.

view the rest of the comments →

onikage ago

My personal security policy is that no one can know my password, not even ME!

GoogleHatesVoat ago

Sounds like military level security. You change it every 30 days and you don't write it down anywhere. Even civilians have to follow the protocol when on DoD systems. Hillary would have never survived as a normal citizen soldier, she would have ended up doing push ups until she puked to use secure systems properly. That or sent off to federal prison. Following the rules is just not her style, she's a thug after all.

count_fagula ago

You change it every 30 days

This is a complete and utter bollocks security policy. What's more secure, a series of Password1!, Password2! derivatives or a tough fucker like Chek2frecAl+ that you choose ONCE? At least NIST agrees with me now

BTW, the password above was generated by apg on Linux, probably there are Windows apps for pronouncable-password generation too. Can't be arsed to look for them at the moment though.

L_Etranger ago

Until the plain text DB gets compromised. But that's more a reason to not reuse passwords.

ThatsThat ago

That's why it is best practice to not store the passwords, but salted hashes of them.

L_Etranger ago

No shit. The salt is good to protect you from rainbow tables. But you don't control other sites' security practices and many don't do it well.