You are viewing a single thread.
View all comments View context
2 points

Password managers holds the key to all my other accounts, where as a random poorly secured site do not

You admitted your passwords are not unique or random, so they do in fact have a definite insight into your other passwords.

a compromised host means I also lose my banking and work account

All password managers recommended in this thread use the master password to encrypt your data.

a compromised host

As suiggested, there are self-hosted versions of these password managers so you don’t necessarily need to trust a host

but that is just not how hash works

You are holding onto the “hash” premise but you aren’t guarenteed that your passwords are being hashed. As I said before, if a site is compromised and your not-random password is leaked, you are vulnerable to having all of your accounts exposed.

I think you are set in your ways, I have tried to enlighten you. I hope your choices don’t come back to bite you in the future.

permalink
report
parent
reply
0 points
*

if you’re interested, look up how modern encryption and password cracking works. Theres really no way for me to explain why what I’m doing is more secure than a manager when you don’t even know what “unique” or “random” means in encryption, let alone how to maximize them for security.

In anycase thanks for all the suggestions

permalink
report
parent
reply
1 point

I totally understand. I think you’re missing my point.

I am willing to bet multiple sites we both signed up store their passwords in cleartext (or unsalted hashes, or broken hashing methods).

So the attackers now have one of our passwords. They may even have a number of our passwords. In my case, using a password manager, the attacker has multiple completely random strings that I have used as passwords. In your case, the attacker has 2 passwords that look very much the same, although a little changed. You are now screwed.

permalink
report
parent
reply
0 points
*

Then you should know that attackers don’t take your plain-text or cracked password and the start manually guessing similar codes on your other accounts, unless they are exactly the same. They always need to get a copy of your password (we’ll assume its hashed), then start the guess work using a decoder.

How secure your password is to the program depend on its entropy, which depends on the password’s length and possible characters. Two passwords are either exactly the same or completely different, and not how similar it “looks” to human.

Now, obviously if you make a easy-to-guess scramble (e.g. password123 becomes password123facebook for, well, facebook) then the hacker can do a custom decoder and this does compromise security. There are a lot of little tricks to avoid this, in anycase it will be secure as long as you maintain a high entropy.

permalink
report
parent
reply

Android

!android@lemmy.world

Create post

DROID DOES

Welcome to the droidymcdroidface-iest, Lemmyest (Lemmiest), test, bestest, phoniest, pluckiest, snarkiest, and spiciest Android community on Lemmy (Do not respond)! Here you can participate in amazing discussions and events relating to all things Android.

The rules for posting and commenting, besides the rules defined here for lemmy.world, are as follows:

Rules


1. All posts must be relevant to Android devices/operating system.


2. Posts cannot be illegal or NSFW material.


3. No spam, self promotion, or upvote farming. Sources engaging in these behavior will be added to the Blacklist.


4. Non-whitelisted bots will be banned.


5. Engage respectfully: Harassment, flamebaiting, bad faith engagement, or agenda posting will result in your posts being removed. Excessive violations will result in temporary or permanent ban, depending on severity.


6. Memes are not allowed to be posts, but are allowed in the comments.


7. Posts from clickbait sources are heavily discouraged. Please de-clickbait titles if it needs to be submitted.


8. Submission statements of any length composed of your own thoughts inside the post text field are mandatory for any microblog posts, and are optional but recommended for article/image/video posts.


Community Resources:


We are Android girls*,

In our Lemmy.world.

The back is plastic,

It’s fantastic.

*Well, not just girls: people of all gender identities are welcomed here.


Our Partner Communities:

!android@lemmy.ml


Community stats

  • 2.8K

    Monthly active users

  • 1.5K

    Posts

  • 29K

    Comments