This seems like one picked up data packet away from being a bad idea. Am I overthinking this?
post
That's fucked up, they should not do that. Even if they do it in a way that users are actually secure (maybe generating the password in the browser, nothing serverside?), it isn't good to train people to trust a website for this.
I've started using https://neal.fun/password-game/ to generate passwords 😊
If you're going to auto generate passwords, just use BitWarden.
The difference in complexity in setting up bitwarden and using your own self-hosted instance of bitwarden is fucking massive. For 99.9% of people rhem using bitwarden would greatly improve their password security and bitwarden has proven to be better than the competition.
FYI Vaultwarden is simpler and should be easier to self-host
Lol, no. I don't trust myselft to keep it well maintained, up to date, nor available when it matters most.
Most people can not host it. Of those who can, many shouldn't host it, for their own safety.
I like the little tools like this that DuckDuckGo has. A couple others:
- "color picker"
- "base64 encode your_text_here" (and "base64 decode encoded_string_here" as well)
- "json formatter"
my favorite is "qr code" best and easiest qr code generator
Whoa, that one is great.
I like this as most qr generator websites make a link shortener kind of thing and put ads before my content.
I would definitely use those passwords! /s
$ Openssl rand 16 | base64
Or just use your password manager. Where you save that password.
Ok but you should use passphrases. Better to type and remember in case you need to
There are instances where sites prevent copy-paste, or you are on another machine without your password manager available
If you have a password vault, use the vault first.
For rotating PC login credentials, I use codified passphrases. They typically meet security needs, are unique and nearly unguessable because it could be ANYTHING in your office, and don't contain dictionary words. Example:
Annual evaluations are due before summer. Be sure to mention the Grodsky project! aeadB4S.Bs2mtGp.
Where did Julie's candy go? I ate it! She'll never know >:D
WdJcg?I8i!Snn>:D
Even if I had a perfectly secure connection, I'm still getting a password from a service that could be tracking me.
WdJcg?I8i!Snnk>:D
That's great if you only have a couple of online accounts, but get past a few dozen and you're toast. I don't know about you, but I sure can't remember 50+ unique pass phrases. However, I can remember the one for my password manager, which has 30+ random character passwords for all my accounts.
Pass phrases for things that need to be human readable/rememberable.
Generated strings for everything else.
Because a pass phrase is inherently vulnerable to a dictionary attack because... it is words. You can obfuscate that but all the ways that would actually not compromise the readability are also pretty well known (whether that is "a=@" or "every 'e' is a 'b'" and so forth.
Is a 96 character pass phrase meaningfully more vulnerable than a 16 character generated string? That gets into the realm of hypotheticals and "one day we'll have quantum computers" but you are generally looking at a situation where everything is fucked anyway or there is a very targeted attack on you... at which point "hmm. 96 characters? Must be a pass phrase". So... not the venue to discuss.
But, at that point... if you are using a password manager/vault anyway...
Also the reality is that anyone who has ever dealt with a bank or some other "legacy" website rapidly learns that there are max lengths for passwords because they are more afraid of allocating a few extra megabytes for the SQL database than anything else. At which point your pass phrase goes out the window and you are back to "p@$$w0rd" level bullshit (or, better yet, you have a mental model/style of password).
Or just use a locally hosted password generator for one that isn't handfed to you by a for-profit company...
Alternatively, you can just roll your face on the keyboard and then take a screenshot of the resulting password to save it. 🤷♂️
Short password please.
-"Penis"
top 50 comments