Skip to content

Comment on AmEx: "We discourage the use of special characters because..."parent

Comments

I disagree. Just using a tiny variation, like adding the length of the website's name at the end, will be enough to defeat any automated system. Even for a human, figuring it out would require cracking several websites and a lot of brain cycles to spend on his particular account.

Well, if he used the same strong password everywhere, it would still defeat any automated system. The reason you don't use the same password everywhere is in case someone decides to try it with your email address in a bunch of different places.

If I found his password for this site was hunter2HN, I'm pretty sure I could guess his Facebook password...

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.