Skip to content

Comment on On cryptography and dogmasparent

Comments

Sure, but I suspect the 16 chars requirement is too much. It is simpler for users to remember $t33.llar10 then a 16 chars password IMHO in most cases. If you make it hard to accept for users they'll end with the same small world repeated N times.

Here we are entering in the field of the "user component" as well. It is pretty hard...

You're making the fallacy of assuming whats easy for you is easy for everyone else. As the xkcd comic pointed out, which is easier to remember? "x1.Tlm98" or "trix are for kids!"

If you try to remember your password, you've done something horribly wrong. 99% of my passwords come straight out of pwgen, and I immediately have my browser remember them so I don't have to.

Those of us with the right kind of memory system (patterned numbers and letters go straight to long-term until no longer needed, can't remember the fancy Latin word for it) have no problem memorizing any kind of password, as long as it is not both extra-long and extra-meaningless. Of course, I'm also the kind of person that doesn't trust password managers.

Having the ability to memorize passwords helps, since you obviously have to memorize at least a couple of passwords (such as those for your personal system). I'd just argue that when you have dozens of sites you use (which you hopefully use different passwords on), you shouldn't try to memorize passwords for them all, just generate passwords and have your browser remember them.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.