My personal method is passphrase + first three characters of domain + number + !
Eg foobarYCO2018!
Easy to remember, unique and doesn't rely on third-party services.
Eg foobarYCO2018!
Easy to remember, unique and doesn't rely on third-party services.
bcrypt(passphrase + "domain.com")[:32]
But anything requiring a calculation step seems to lose a lot of the advantages of a single-passphrase system.Sure, it's a form of security through obscurity, but aren't we essentially relying on our computer systems' flaws remaining obscured to not get hacked?
Browser and operating system vendors aren't especially smart either, but at least it's thousands of white hats vs thousands of black hats, instead of thousands of black hats vs just you.