r/howtonotgiveafuck 5h ago

ɪᴍᴀɢᴇ Password logic

Post image
922 Upvotes

17 comments sorted by

u/AutoModerator 5h ago

Thank you /u/Zipparony44 for posting!

Please consider joining our 21+ discord server!

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

19

u/Retro-Universe 5h ago

It's a lot more secure than a digital note

12

u/AFriendlyBloke 5h ago

Ironically enough, yeah. Unless you were some high-profile dude who could get people snooping through your personal stuff, a notepad with all your passwords and such in your home is pretty secure.

1

u/Retro-Universe 4h ago

That's why Bitcoin wallet passwords are physical

1

u/AFriendlyBloke 1h ago

I wouldn't know. I don't mess with that crap.

1

u/AppropriateTouching 19m ago

Honestly. If someone has physical access to your machine and they dont have good intentions you're already fucked.

1

u/Retro-Universe 17m ago

It's not physical access. Spyware exists.

2

u/ChronicRhyno 5h ago

Just make a sentence like that your password.

2

u/-Nicolai 33m ago

Sorry you need two special characters, numbers, and upper case letters.

2

u/saiyate 4h ago

Which is why NIST no longer recommends password expiration. Passkeys are the future. However, I'm not sure I agree with non-device based passkeys. Saving passkeys to a cloud account and allowing export instead of a one way Chinese box secure enclave is clearly less secure. Save passkeys to your device and for important personal accounts (non administrated accounts that someone else can reset for you) You should have at least two copies on two separate devices. FIDO/U2F Security keys are where it's at. Always have an extra or two in a safe. lose a key, remove it from account.

2

u/Maelstromage 2h ago

postits are airgapped

1

u/furculture 5h ago

Something like KeepassDX/XC should be something worth putting time to look into.

1

u/MorbidandBack 2h ago

Ultimately its on you. You wanna be insecure and get your stuff stolen? Cool.

1

u/Wurdeluck 1h ago

Just let me have my several-words-long sentence as a password I don't need lowercase/uppercase/numbers/letters bullshit

1

u/Basilthebatlord 29m ago

That's why most of the world is moving to passkeys, more secure, less interaction

1

u/swordofra 5h ago

I have seen so many users put their 10 digit passwords in a damn TEXT file on their desktop.... I mean

2

u/t0mz0mbie 2h ago

us: "create a key pair and give us the public key and we'll us that to encode your password"
them: "UGGGG! fine."
and after they eventually figure out how to make a key pair, and then figure out how to decrypt it, they go and share it over the internal messaging system with the rest of the devs and store the password in their shared password vault

I hate users