• Lord Wiggle@lemmy.world
    link
    fedilink
    arrow-up
    3
    ·
    7 hours ago

    I got hacked. My browser got copied with all stored passwords. Which were almost all the same, for about 20 years. And my payment info. Purchases were made, accounts were used to spread malware through purchased ads. Accounts were banned. In the end I managed to get most of my money back, I ended up with a loss of only 30 euros.

    I never store passwords in my browser anymore, I never click “remember me” or “stay logged in”, I use 2FA when possible and I use a password manager with randomly generated long passwords.

  • AbsolutelyNotAVelociraptor@sh.itjust.works
    link
    fedilink
    arrow-up
    23
    ·
    edit-2
    1 day ago

    Generating a password (or, actually, anything in general that involved some imagination and abstract creation) was the bane of my existence.

    So when I managed to find an ingenious password that was both easy to remember and not obvious without the right hint, I was thrilled. I used it for 10 years straight.

    Fortunately, the internet then was not the dangerous place it is now so you could safely reuse passwords everywhere.

    Then I discovered password managers and they changed my life. There’s only one password I need to remember now.

      • AbsolutelyNotAVelociraptor@sh.itjust.works
        link
        fedilink
        arrow-up
        8
        ·
        edit-2
        1 day ago

        The trick is using something you can easily remember but also not obvious. For example: take your favorite book, pick the first sentence of the first chapter and change vowels with numbers. There, super easy to remember password, but almost impossible to guess.

        Instead, you can use anything: the second sentence of the book, the name of your favourite song (or songs if the song is just one word), the lyrics of that song…

        Just something that is easily accessible in case you forget but nobody could ever guess

        • toynbee@lemmy.world
          link
          fedilink
          arrow-up
          1
          ·
          6 hours ago

          This and similar advice always reminds me of - IIRC - one of the Halo novels, which briefly featured a character logging in to read his corporate email. To do so he had to enter his password, ThereOnceWasAGirl; but he, the fool, accidentally entered ThereOncewasAGirl.

          If it wasn’t Halo, it was a similar type of story and this seemed an odd detail to include.

  • Flax@feddit.uk
    link
    fedilink
    English
    arrow-up
    9
    arrow-down
    2
    ·
    edit-2
    1 day ago

    I also like Lemmy’s feature where it censors your password if you type it out. Here’s mine:

    **************
    
  • HeyJoe@lemmy.world
    link
    fedilink
    arrow-up
    5
    ·
    1 day ago

    I thought i was so clever using qwerty123 back then. Then I realized its super common…

  • modifier@lemmy.ca
    link
    fedilink
    arrow-up
    3
    ·
    1 day ago

    When I don’t have a password autogen something for me, I am still using a variant of my original autogenerated geocities password from my days on the SunsetStrip. I’ve just buttressed it with additional letters and numbers as password requirements have changed.