Skip to content

Comment on So I lost my OpenBSD FDE password (2016)parent

Comments

"with our approach to information security"

Yeah, especially here on HN you hear about people not thinking about threat models. And yes, Denial-of-service by forgetting the password or having it inaccessible is a threat model

That's why I just laugh at the people who think putting everything in a password manager is the best way. It is good, but you need to understand your cases/threats and risks

Sometimes writing it in a piece of paper is the best solution

Writing passwords on a sticky note on the bottom of your keyboard in an office is obviously a bad practice. A unique string password on a piece of paper in a drawer at home only you would normally have access to? Not clear. And obviously you can hide things in a house more thoroughly than that with the risk that you get too clever.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.