Skip to content

Comment on Ask HN: Alternatives to a password manager?

Comments

Use two factor where possible, but for the password, here's an easy format that I use to generate a strong and (somewhat) unique password per site:

1. Choose you paraphrase - something like "I like long walks on the beach after seven"

2. Take the first letters to give you something like this: iLLwotBa7

3. Throw a symbol on the end: iLLwotBa7?

4. Append a 3 letter site name acroym in a similar way to the phrase (I use 3 for consistency): iLLwotBa7?hkn

5. Throw on another symbol: Append a 3 letter site name acroym in a similar way to the phrase (I use 3 for consistency): iLLwotBa7?hkn!

That's what I do, so I only have to remember the 3 letter for each site. Here's some more: Reddit - rdt, Gmail - gml, etc.

I like the approach but why not use the full site name instead of a 3 letter acronym? It would be easier to remember. Is it just in case of a leak the link between the acronym and the site is not easily spotted?

I suppose because its a dead giveaway to that part of the string of the password and if the point is to make it look random and secure, you don't want to be using the real site name for obvious reasons

Thanks for sharing. I think I am going to switch to a scheme like this.

Apologies for the formatting, I am on my iPhone.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.