Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I've struggled with this, the issue to me is by their very nature I want those passwords that can be used for bootstrapping/resetting everything else to be very strong ones. I've settled with making a list, encrypting it with a memorized moderately-strong passphrase, and storing copies (flash drive or base64-on-paper) in a few physically secure locations that probably won't all get destroyed at once. Maybe this is overly paranoid but it wasn't a huge amount of effort, either. At least I am pretty confident the weak links are now the security of those services themselves (and my client computers) and not the passwords.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: