Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Also why would you allow either password based and root login when you are "pretty careful with machine security"?

I had to smirk when I clicked on complex password scheme.



I found that password scheme pretty OCD and not very secure considering once you have that paper, you have a pretty good chance of very quickly brute-forcing your way in.


If someone breaks into your house or office to get that piece of paper, your problems are bigger than a compromised server.


But a piece of paper is easier to snatch than having your passwords written down nowhere - without stealing a whole wallet or breaking into houses.


If having your password on a note is good enough for Schneier ( http://www.schneier.com/blog/archives/2005/06/write_down_you... ), it's good enough for me. For pretty much the same reason. If you're going to even use a password, it should be a good one. And if it's a good one, you aren't very likely to be able to memorize it.


With upper and lower case and "1337" speak thrown in between and a few other characters replaced, it should not be that hard to come up with a decent enough password that you can even remember.

And why not a password manager instead of paper? Would be even better if it was one that reads your fingerprint or so.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: