Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Here's a format I really like:

3CatsHave12Legs!

Easy to memorize, and pretty strong.



The vast majority of passwords does not need to be easy to memorize because they should be stored in a password manager. In fact, I'd argue that the harder it is to memorize, the stronger the password.

Yet they still need to be typed on cell phone keyboards, TVs, or communicated over phone (shared passwords are the best compromise if asymmetric cryptography is not an option), in which case you usually need to spell it out anyway.


Cell phone keyboards should have a "QR code input" and then you could just use a QR code generated by your password manager dynamically.


Why mention memorizing passwords? Most people have dozens of passwords, and most people would have trouble memorizing even a simple word for dozens of passwords. I have a lot of trouble with those annoying security questions which one would assume would be constant and easy to answer.


Have you not memorized the password to your password manager?

How would that even work?


FaceID or YubiKey


Ok, but if there isn't a high-entropy sequence of "something you know" somewhere in the system, you've created some pretty bad failure modes. 1Password requires a master password periodically, but can otherwise be unlocked by AppleID (presumably also true for secure-element biometrics on other platforms).

I maintain that a good secrets management system has a number of passwords which should be memorizable (and memorized) which is greater than zero. Possibly by only one element.


Every password manager I know of, including Apple's, requires a strong password to unlock the vault. FaceID or YubiKey allow me to bypass typing that so often, but anyone trying to get into my accounts or password manager would have to know the strong password and get past the physical/biometric 2FA.


How many more passwords of this format can you construct? `have` is fixed, the `!` at the end is a classic, and the 12 number is pre-determined by true cats and the 3. So the only degrees of freedom you have are:

- the entity number (3)

- the kind of entity (Cats)

- the kind of part (Legs)

and that's not a huge number of combinations.


"My4BikesHave9WheelsBecause1IsATricycle?" is a valid one for example?


The question mark makes this look like it's the title of a new hit light novel


You have to type that all in without error and the archaic app needs to actually support that many characters


Typing that all in without error is considerably easier than typing TMJ0ltu*zif52Cb& in without error.


I write longer passwords than that periodically. Archaic applications will get shorter variants. No two app will share the same password.

All are no problems for me. With or without a password manager.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: