Hacker News new | past | comments | ask | show | jobs | submit login

-



Please don't do that because it invites users to try it out and while you probably don't try to be malicious, I know that it is a pretty common scam in MMORPGs. People say in chat: awesome, if I type my password it becomes: [hidden] and hopes other users try that. As soon as something looks like their password, they have scripts ready to immediately change the users password.


Although your advice about "not writing your password here" is well-intentioned, the reality is that most passwords are already available in private blackhat databases.

Memorizing and reusing a single password is the worst thing you can do. The number of leaks and brute-force attacks are increasing, and you should really be generating random and unique passwords per website if you aren't.

To get an idea of how easy it is to crack a leaked password, download a public list of a website you know[1] (ex. L1nk3d1n), you'll probably find the password you used at the time of their leak in the list, since ~97% of them have already been cracked.

[1] https://hashes.org/public.php


This has nothing to do with the submission, and only has the most tenuous connection to the parent comment.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: