79
Comments (22)
sorted by:
You're viewing a single comment thread. View all comments, or full comment thread.
1
CSIS_CIA_pure-evil 1 point ago +1 / -0

Normally, a web site will save the hash of the password, not the actual password.

Anytime a web site sends you your password when you request "lost password", you have a dangerous site.

Get keypassx to keep track of the passwords, and generate a unique password for every site.

Don't use the same password on multiple sites. use a xkcd inspired password generator for easy to remember passwords. "shade sell none gun" or "cream correctly single cheese" for example. Long stupid phrases are just as secure as impossible to remember alphanumeric crap.

1
CSIS_CIA_pure-evil 1 point ago +1 / -0

https://xkpasswd.net/s/ look at the cartoon, then play with the password generator. XKCD refers to the comic.

If you can run a perl program, you can download the generator. That way you know that the internet has never seen your pass phrase before. Don't ever google your password either. Just generate until you find something hilarious and use that.