• chiliedogg@lemmy.world
    link
    fedilink
    arrow-up
    2
    ·
    4 hours ago

    Just add one to the number each time.

    I’m on “[passwordiveusedforyears]22!” at work.

    For otherwebsites I’m on things like “[passwordIveusedforyears][websitename]!”

    Proper 2FA is secure enough for most people to keep using the same password so long as it hasn’t been compromised. And a few things, like work passwords, email passwords, and bank passwords should be unique to thaspecific account.

    Really, the biggest security hole is requiring logins for fucking everything. That’s why there’s a million password leaks. Why does a news website need me to sign in? Why do I need an account and password to order a pizza that I’m gonna pay for in-person?

    • MrShankles@reddthat.com
      link
      fedilink
      arrow-up
      1
      ·
      2 hours ago

      I do like using a good passphrase that includes the website name

      Eventually, I’d like to switch to all generated through bitwarden or keypass, but I’d prefer to self-host when going that route