Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> Compare it to an algorithm, where your attack surface is "every service." If one password is compromised, they all are.

My password for Amazon is "f3cfcb6ZUZ^". What's my algorithm?



Doesn't really matter because it's too short. Crackable in 10 seconds if the password hashing is poorly implemented. (I assume Amazon implements good hashing, but that's besides the point. Your algorithm generates passwords that are just a bit too short.)

https://lowe.github.io/tryzxcvbn/

https://blog.codinghorror.com/your-password-is-too-damn-shor...




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: