Skip to content

Comment on Ask HN: How do you manage your passwords?

Comments

For credentials like facebook, emails, coinbase and etc, my password will be [identifier]_mypassword. So for example, my fb password will be facebook_yyu9023, email password will be gmail_yyu9023 and the patterns continue. Now days I just write it down and then encrypt it with a passphrase.

I tried the identifier route before, but there's always a few smart aleks who detect and refuse dictionary words, maybe even the domain name (can't remember exactly). These types of "systems" that live in your head, would be the best way to go if it weren't for banking, financial institutions, and government run websites.

With that being said I use LastPass for the high priority stuff and 1 basic password for sites I could care less about. Never lost one of those basic accounts yet.

I use a variation of the identifier route which is to take the identifier and drop all the vowels from it. So not only do I get something that is easy to recreate it's also not in the dictionary.

What if someone gets hold of one of your passwords and then sees that pattern and tries it out on all the other websites?

In that case you are doomed. You'll have to change all passwords to all sites after one has been compromised.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.