Disclaimer: I use a password manager, so please don’t direct your comments at me.
So I know this person that says they don’t use a password manager because they have a better system like… I’m gonna give an example:
Lets say, a person loves Star Wars, and their favorite character is Yoda. The favorite Their favorite phrase is from The Good Place “This is the Bad Place!”. And their favorite date is 1969 July 20th (first landing on moon).
So here:
Star Wars Yoda = SWYd
“This is the Bad Place!” = ThIThBaPl!
1969 July 20 —> 69 07 20
So they have this “core” password = SWydThIThBaPl!690720
Then for each website, they add the website’s first and last 2 characters of the name to the front of the password…
So, “Lemmy Forum” = leum
Add this to the beginning of the “core” password it becomes:
leumSWydThIThBaPl!690720
For Protomail Email it’s: prilSWydThIThBaPl!690720
For Amazon Shopping it’s: amngSWydThIThBaPl!690720
Get the idea?
The person says that, since the beginning of the password is unique, its “unhackable”, and that the attacker would need like 3 samples of the password to figure out their system.
Is this person’s “password system” actually secure?
Its an example. Not a real password
If you replace the “SWydThIThBaPl!690720” part with a random string like: dsh2box5hRs3wraA (just generated this), but kept the system the same, would your assessment of this system be different? (Assuming someone can actually remember that string of characters)
Your new example is confusing. With or without the date?
In any case, what would be the point? “I can remember the first 4 letters of the password but not the last 20”?
This person needs to understand that they cannot outsmart a machine, at least not in this. FWIW I’ve been using keepassxc for I don’t even remember how many years and never had a problem with it. It has the option to additionally encrypt the database with a file, so if someone steals the database and even manages to guess the password (the only one that I haven’t written down anywhere) they still don’t have access.
“Lemmy Forum” = leumdsh2box5hRs3wraA
Protomail Email = prildsh2box5hRs3wraA
Amazon Shopping = amngdsh2box5hRs3wraA