Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I don't use that because of (unfounded) concerns that I will someday need to enter my password into some device where it's not available, or the domain will change, or some other scenario where bad things will happen because I do not actually know the password I told the site.


I call this 'primary authentication' which means you're in an environment where you can't execute code (staring at your xfce4 desktop log on prompt for example). Password managers and generators are only useful after you've logged on. Form there, you can execute code and use a password manager for 'secondary authentication' (websites, email, etc.).


This is why I use LastPass. I can log in (securely?) to their website and pull up the password out of a database in (rare) situations like that.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: