• pishadoot@sh.itjust.works
    link
    fedilink
    arrow-up
    5
    ·
    10 days ago

    I mean, that’s true if you reuse your passwords instead of using a password manager that can generate random gibberish… Which is itself a very poor habit exactly because of this very fact?

    Even assuming a company follows best practices (a bold assumption that is wholly inconsistent with reality) there’s ALWAYS a possibility of a breach - and it’s not if, it’s only when.

    So, everyone should be using a password manager by default.

    I like to use keepassXC personally because it’s fully under my control. I don’t really care for ones that are hosted by 3rd parties because that introduces more risk if they get beached, but for many people that’s fine; it’s more convenient for the user. To me it’s important enough that I manage it all locally.

    • AugustWest@lemm.ee
      link
      fedilink
      English
      arrow-up
      2
      ·
      edit-2
      10 days ago

      So, everyone should be using a password manager by default.

      And an email mask. Life is easier if you can reset a password and change your email after a breach and have the old email disabled and disappear.

      • pishadoot@sh.itjust.works
        link
        fedilink
        arrow-up
        1
        ·
        9 days ago

        Agreed!

        The pain with email maskers is when a service doesn’t accept the email as valid… I have 2-3 I use. I start with blur (abine/ironvest, whatever you call it these days) and if it doesn’t work I go to my bench warmers.