How much should I care if someone hacks my handle and posts ads on a chat site? Or reads registration-required articles under my registration? Or etc etc.
How much should I care if someone hacks my handle and posts ads on a chat site? Or reads registration-required articles under my registration? Or etc etc.
Just use a password manager. It's easier and it's safer, and you never have to think "is this a low consequence site?" ever again, because you'll have high quality passwords everywhere. It's really the only way to be sure you have unique and strong passwords everywhere.
>why reuse at all?
Because it's easy. There's many sites I create an account for once or twice and I never use again, mainly e-commerce. I don't care if someone logs in, at best they get an address and maybe a few card details. That's all practically public information.
>are you sure? I bet that that's not true
Yup, 100%. And even if a few get missed, anything super important has 2fa, on top of using semi-unique passwords that adhere to a format so I can guess them in <5 attempts if I don't have my password manager on hand. And I check them semi-frequently in haveibeenpwned.
>Just use a password manager.
I agree this is good advice in general but even with decently designed password managers, like dashlane and lastpass, people often don't like to use them for various reasons. My parents get confused by new software. I tell them "use a very strong password for google, amazon, ebay etc, and if any other site asks you for a password use a weaker one". If they used a password manager I guarantee they'd get overwhelmed when it comes to using it on different devices and give up, reverting to worse security than before.
Also in the end, people are astronomically more likely to fall for phishing emails than be the victim of a security breach from password re-use. Seriously the whole "use a password manager with a RNG upper/lower/symbol/number combination" trend is overhyped and honestly a distraction from more pressing security issues. Google estimated phishing victims are 400x more likely to have their accounts compromised than anything else[1]. And as someone who is currently dealing 90% with phishing attacks over any kind of password related incidents I'm very inclined to agree. If you're a public figure and therefore an actual individual target for motivated attackers then yes, use RNG passwords and a password manager with 2fa and only ever store the db on a memory stick which you keep on a chain around your neck, otherwise it's not really necessary.
[1] https://www.bleepingcomputer.com/news/security/google-ranks-...
I have a method I use regardless if 2fa is an option or not.
I have a fairly secure password that I have memorized. Then for each site I pick something about it that I can remember to add on to the password.
For example if my current ebay password is: Pa$$w0rd the new one would be: Pa$$w0rdEb or EbPa$$w0rd Amazon would be: Pa$$w0rdam
That has helped a few people I know keep separate passwords for each site without having to go through a password manager. YMMV of course.
The way I look at it is if the sites DB gets dumped, at least the scripts will fail using the password on other sites, even if it's not the most secure password.
You're point about the phishing e-mails is spot on though. No amount of secure passwords will stop that
Never found any of even the main chunks in the PW lists, but I'm sometimes forced into stupid PWs by stupid rules as in above comments.
2. What kinds of websites that require a sign-in are actually low-consequence? I can't think of any from the top of my head, but that's probably because I'm pretty reluctant to sign up to new sites.
Forum logins risk reputational damage, but otherwise are reasonably limited. Some people use specialist forums to ask one-off questions, for example.
It's usually not a function of the site, but a function of the site and the user. pg would probably care more about his HN account than user051783254. That said, some sites where I expect the majority of users (mostly the non-paying ones, but perhaps even the paying ones depending on the payment mechanism) would probably not care about their accounts being hijacked might include: HN, StackOverflow, CodeProject, AllTrails, Disqus, Last.fm, SlickDeals, etc.
What would worry me is if people hack the login for a low-consequence site and then figure out that those login credentials for this user are the same everywhere: at their bank, Amazon, etc. Personally, I use different passwords at every single website, but at low-consequence websites I sometimes use less secure ones. I don't see how this is a problem (for me).
I understand why low-consequence sites do not implement schemes to force users to use stronger passwords, though. Howls of outrage, lost users, and attempts to get around it, as charDiversity says: https://news.ycombinator.com/item?id=16975773
Or probably: sites that don't involve money.
You may not give much away on one site, but combine all that data across multiple sites, and maybe I can start building a profile on you, identify you, impersonate you, steal your identity, etc.
Why would someone go through that much effort on one person when they can end out a million phishing emails with two minutes of work, get a few thousand replies, get a few hundred people buying their scam and walk away with a six figure payout? The chance of you getting your identity stolen because of password reuse is about as low as getting killed in a terrorist attack: it's not really worth thinking about or putting too much effort into preventing when you're more likely to get hit by a car.
The usual cargo-cult thinking usually ends up with someone leaving their 1024 bit secret key under the doormat, or worrying too much about nation states hacking your routers instead of worrying about Bob clicking a suspicious link.
I don't know about you but I don't like having to remember passwords. But people here can feel free to impress everyone with their memorized password they use on pizzahut.com, right up until they find out that they reused it somewhere important they totally forgot about because they don't have a convenient database of all the websites they have an account on.
Seriously, this counter-culture of being proud to have shitty passwords is the same mindset that makes antivax and climate science deniers a thing. You want to reuse shitty passwords, nobody is stopping you (I've certainly done it), but don't be proud of it and don't shit on people who care more than you.
You should worry about strong passwords, but the point is moot if the rest of the system has other major flaws.
See: people who have their security answer as a long hex string, and customer service doesn't check the digits.
(It's also a good idea to, if you use correct answers, to not leave them on Fb or other places)
My system is two or three "disposable" passwords I use on low reputation sites or sites where I don't care about breaches. I don't care about people knowing it either, if someone asks and I trust them I'll more often than not tell them what it is. Services where compromise would actually affect me get stronger passwords: my Google and Amazon passwords semi-random generated, but sticks to a format so I change parts of it and never forget it, and I check to make sure it's not in breaches every now and again. I use variations of it for my bank, medical stuff, etc where a breach could actually have implications for me.