• Whats_your_reasoning@lemmy.world
      link
      fedilink
      arrow-up
      3
      ·
      6 hours ago

      I use modified “HorseBatteryStaple” style passwords. I have a couple base phrases that I always remember, with special characters and numbers inserted. I modify them bit by bit for different sites, and keep a list of the changes - only the changes. Anyone who looks at the list would see random words, numbers, or symbols without context; only I know how it all fits together.

      For example, let’s pretend HorseBatteryStaple1! Is my default password. I may have “cell phone, machine 5” on the list. That would mean the password for my cell phone’s payment website modifies the default password by changing one of the words in HorseBatteryStaple to “machine” and the number 1 to 5.

      I know password managers exist, but I like to try to remember my own passwords. Especially since I may need them across different devices, including my work laptop that I can’t download new programs onto.

    • UncleGrandPa@lemmy.world
      link
      fedilink
      English
      arrow-up
      2
      arrow-down
      1
      ·
      4 hours ago

      Because they seem to fall into two categories. Those that have been compromised

      And those who haven’t… Yet

      • trxxruraxvr@lemmy.world
        link
        fedilink
        arrow-up
        5
        ·
        edit-2
        6 hours ago

        My employer, a 12 people big company, nowhere near any fortune list, mandates the use of 1password for all company related accounts.

        • oppy1984@lemdro.id
          link
          fedilink
          English
          arrow-up
          4
          ·
          6 hours ago

          Ah but you see there’s the problem, you don’t have a committee to launch a working group that puts together investigative teams to research and write reports on the benefit of the solution, the ROI of the solution, the training costs of the solution, stakeholder buy in of the solution, and potential alternatives to the solution. You need at least a 10 month process before one jackass says they don’t want the solution so the committee can recommend to management that the solution be abandoned.

    • Booboofinger@lemmy.world
      link
      fedilink
      arrow-up
      2
      ·
      9 hours ago

      I basically use a childhood limerick in leetspeak. Easy to remember, tough to Crack. Like for example, Peter Piper pickedna peck of pickled peppers becomes “P3t3rP1p3rP1ck3d4P3ck0fP1ckl3dP3pp3rz!” Of course I never used that particular one, but you get the idea.

    • jawa21@piefed.blahaj.zone
      link
      fedilink
      English
      arrow-up
      1
      arrow-down
      1
      ·
      7 hours ago

      I function by only having 2 accounts I actually care about. Bank and e-mail. The rest get the same password over and over because I legitimately don’t care about them and never give them real personal data.

      • naticus@lemmy.world
        link
        fedilink
        English
        arrow-up
        20
        ·
        14 hours ago

        Yeah idk about that. I’ve worked in state govt for a very long time and our cybersecurity controls essentially mandates we use one. I’m also in our security audit team and have to talk to state offices about our NIST controls regularly. And the NIST DOD controls are even more stringent than ours. Something sounds off.

          • DaGeek247@fedia.io
            link
            fedilink
            arrow-up
            1
            arrow-down
            1
            ·
            4 hours ago

            Not gonna get specific, but, I have access to a shitload of sensitive personal data. It’s more likely you ran into an agency policy rather than a federal policy.

      • bdonvr@thelemmy.club
        link
        fedilink
        arrow-up
        4
        ·
        14 hours ago

        Okay so remember the one or two ones you need there (try a passphrase!)

        For everything else - password manager.

    • theneverfox@pawb.social
      link
      fedilink
      English
      arrow-up
      5
      arrow-down
      13
      ·
      15 hours ago

      Those are hackable too through

      I have passwords I don’t care about, passwords I keep on the manager, and then important ones I enter manually every time