Password Utilities as a Single Point of Failure
hashedapp.com
hashedapp.com
sitename.com: c4 - t/5r
sitemore.com: mrc - pp:9
If someone manually digs around, they can find what the usernames 'c4' and 'mrc' stand for. However, nobody other than me knows what 't/5r' and 'pp:9' expand to and I will never forget what they mean. Sure, it does theoretically make it slightly easier to brute-force my passwords but if 't/5r' = 'tempest/ariel5randa' then brute-force will take forever anyway.If the browser doesn't auto-fill the password, I just have to look up a single list and takes me seconds to type the password. Whenever I sign up for a new site, I just add the username/password hint and forget about it. I've been using this system for well over a decade and have never had any login problems anywhere.
/-/
**
1m;
Feel free to login to any of my accounts. And I do keep most types of accounts separate. Bank password is different from Credit Card is different from email is different from HN.I do believe that the single most important account for one to protect is one's e-mail account.
The only factor I’m unsure about is the hashing algorithm: I’m not sure whether either SuperGenPass’s or PwdHash’s is safe. I couldn’t find what PwdHash’s algorithm was after a quick look on its site. SuperGenPass uses multiple iterations of MD5 – bcrypt would be a better algorithm, but I don’t know whether repeated-MD5 is unsafe or acceptable. (The aspect of the hashing algorithms I’m worried about is the speed at which an attacker can brute-force the password.)
1) Use N-factor auth: fobs, authenticators, otps, etc.
2) N-person keying: require multiple people to enter their part of the password known only to them.
3) Delegate lower privilege access for day-to-day usage, versus aforementioned grand master password that is split amongst multiple people. This means lowering the exposure of a password.
This is in addition to not using the same password anywhere else and not having a guessable password scheme.
I've used and refined this over a number of years, and now I'm very happy with it.
Enjoy!
This is what i use to ensure i have a differing password for every site, It also has a standalone JavaScript webpage for mobility and ensuring that the extension not updating doesn't screw you over purposes.
Furthermore lastpass supports youbi key so it supports two-factor auth.