Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I have perhaps 6 passwords:

1) My email password, which is randomly generated but memorized, and reused nowhere.

2,3,4) A handful of passwords, call them grade A, B and C, which are used in conjunction with SuperGenPass to generate passwords specific to a website. Only the top level domain is used; for rare cases where the URL changes but the password doesn't (like amazon.co.uk vs amazon.com) I have chosen one TLD as the canonical one. The ratios of usage of A, B and C are approximately 1:2:50. No website I log in to ever shares its literal password with any other.

5) Computer account login password, this is changed every 3 months.

6) Encryption keys passphrase. Should I have anything that I want to keep private and not leak anywhere, or signing keys etc., I use a combination of letters, numbers and symbols, over 40 characters long.

Bank passwords (actually more usually numbers) and the like I have written down, unlabelled, in secure locations and memorized from frequent use.



Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: