Hacker News new | past | comments | ask | show | jobs | submit login

Because it's intrusive. There are lots of opinions on how far a website should go to ensure their users select strong passwords, but I implement a strawman password roster.

If some of the throwaway sites and forums that I sign up to once started forcing me to select a more secure password it would be extremely annoying and I wouldn't sign up.

I'm perfectly happy with my 6 letter a-z password for one time forums, that I use anonymously, and that I might occassionally log back into twice.

Incidentally, the password I use is "openit". This password means nothing to me. If you did some detective work on me I'm 100% sure that you would be able to get access to some sites that I use by entering that password.

Not having to use symbols, capitals, and strong passwords for these throwaway sites, means that I can effectively maintain about 10 different password sets, where my most important "tier 1" passwords are reserved for my SSH keys and email.




I'd be curious how many 'throwaway' passwords are "sesame".




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: