Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Around 20 characters using something like http://xkcd.com/936/ is both safe and reasonably easy to recall.


Unless you actually randomly select the words, I'm fairly sure that the analysis of strength of that strategy is flawed. And if you do randomly select the words, I'm not sure how easy they are to recall. And, I'm really skeptical how easy it is to recall different word sequences for 100 different web sites.

I've quizzed most of the people I've encountered who claim to use this technique. They all use four words that "pop into their head". That's quite a big different from using random words, and almost certainly much weaker.


I tried this method. I probably did use totally random words because I can never remember what the password was and have to reset it every time I want to use the site I'm testing this on!




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: