A new login technique is becoming available in 2023: the passkey. The passkey promises to solve phishing and prevent password reuse. But lots of smart and security-oriented folks are confused about what exactly a passkey is. There’s a good reason for that. A passkey is in some sense one of two (or three) different things, depending on how it’s stored.
Your system is most likely way less secure than you think. I mean, possibly not since you’re here, but most schemes are trivial to solve even automatically.
…and that doesn’t really matter either, because so many people have such shitty passwords (and use the same ones everywhere) that noone really bothers checking for permutations when they have thousands of valid accounts.
But if truly enough people are convinced to be more secure your scheme may eventually become a target, too.
With passkeys (and password managers in general) the security gets so good that the vast majority of current attacks on passeord protection get obsolete.
I agree 100%. As mentioned, I rarely share my approach and I’ll be deleting that comment in a bit. It works well for me.
No hacker is attempting to decode the password algorithm because they don’t know of its existence on my logins, and they have thousands of better ways to go - as you said.
Your system is most likely way less secure than you think. I mean, possibly not since you’re here, but most schemes are trivial to solve even automatically.
…and that doesn’t really matter either, because so many people have such shitty passwords (and use the same ones everywhere) that noone really bothers checking for permutations when they have thousands of valid accounts.
But if truly enough people are convinced to be more secure your scheme may eventually become a target, too.
With passkeys (and password managers in general) the security gets so good that the vast majority of current attacks on passeord protection get obsolete.
I agree 100%. As mentioned, I rarely share my approach and I’ll be deleting that comment in a bit. It works well for me.
No hacker is attempting to decode the password algorithm because they don’t know of its existence on my logins, and they have thousands of better ways to go - as you said.