Skip to content

Comment on Can the world please standardize passwords?

Comments

Most passwords don't matter. The example I always use is if someone guesses my HN password, so what? [1] HN is not my bank. It does not need serious security in regard to my use (not speaking for anyone else). Giving it a unique low quality password is fine. Facebook demands a bit more attention, gmail more beyond that, but neither requires life and death security either.

One reason for no single standard is there is no single level of risk. The other is that standardizing password formats makes cracking passwords more standard.

[1]: Though, I did change the trivial password I was using before first posting the example here on HN

If you have higher security accounts which have gmail as the contact email, then the gmail account should be treated the same.

Breaking into gmail gives access to many password recovery mechanisms.

But I agree for low priority sites: my password across many forum sites is the same and very low entropy. I really don't care to think more about it!

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.