Defensive Computing Checklist
defensivecomputingchecklist.com
defensivecomputingchecklist.com
E.g. using the BaseballRules!<word> formula for your passwords gives you decent protection from completely automated attacks with no feedback loop. But if a human intercepts just one of these passwords, then they can easily brute-force their way to any of your accounts that doesn't have some sort of 2FA. Not nice. And good luck remembering the special <word> for more than a handful of web sites.
Plus, xeroxing/printing your password list is also not as benign as it sounds. Any professional copying machines or printer typically includes some sort of non-volatile memory, that could be used to recover recent printouts.
https://michaelhorowitz.com/BestPasswordAdvice.php
A formula is one approach that people should consider and it is often overlooked. The blog also makes a clear distinction between hard and soft formulas (my terms) A soft formula can not be cracked, even if many of the passwords leak. Michael Horowitz
- When you get a text message, you have no idea who sent it
- When you get an email message, you have no idea who sent it
- When you get a phone call, you have no idea who the caller is