logoalt Hacker News

empyrrhicistyesterday at 4:23 PM2 repliesview on HN

It's easier for me to remember really long passphrases than even short alphanumeric strings - small maximum password lengths set my teeth on edge. The passwords should be getting hashed anyway right?


Replies

raddanyesterday at 5:35 PM

The problem is that you never really know what a website operator does with your credentials. Ideally, you have both a unique email and a unique password for each site, because sadly credential stuffing [1] is a thing.

[1] https://en.wikipedia.org/wiki/Credential_stuffing

abustamamyesterday at 4:31 PM

Should being the operative word...