view the rest of the comments
Android
DROID DOES
Welcome to the droidymcdroidface-iest, Lemmyest (Lemmiest), test, bestest, phoniest, pluckiest, snarkiest, and spiciest Android community on Lemmy (Do not respond)! Here you can participate in amazing discussions and events relating to all things Android.
The rules for posting and commenting, besides the rules defined here for lemmy.world, are as follows:
Rules
1. All posts must be relevant to Android devices/operating system.
2. Posts cannot be illegal or NSFW material.
3. No spam, self promotion, or upvote farming. Sources engaging in these behavior will be added to the Blacklist.
4. Non-whitelisted bots will be banned.
5. Engage respectfully: Harassment, flamebaiting, bad faith engagement, or agenda posting will result in your posts being removed. Excessive violations will result in temporary or permanent ban, depending on severity.
6. Memes are not allowed to be posts, but are allowed in the comments.
7. Posts from clickbait sources are heavily discouraged. Please de-clickbait titles if it needs to be submitted.
8. Submission statements of any length composed of your own thoughts inside the post text field are mandatory for any microblog posts, and are optional but recommended for article/image/video posts.
Community Resources:
We are Android girls*,
In our Lemmy.world.
The back is plastic,
It's fantastic.
*Well, not just girls: people of all gender identities are welcomed here.
Our Partner Communities:
Oh they absolutely do.
You keep going back to hashing methodology. I totally agree that if the website hashes your password correctly, its unlikely to be compromised.
That said, you are trusting the website in that regard, when it has been repeatedly proven that there are sites, even large ones, have exposed passwords.
You said at the beginning of this thread that you can't trust password managers to manage your password correctly. But you trust random websites with that password instead.
So put your hashing discussion to one side, and think of the scenerio where your passwords are not encrypted. Because you can't guarentee that they are.
What got me into this discussion was your comment
It is just such bad advice. Anyone who thinks changing a few letters in their password used accross multiple sites deserves to be hacked.
Edit: I'm going to stop here. I don't think I'm getting through. Thanks for the chat.
I’ll just finish off with a few more points
If your password is unencrypted or poorly encrypted, having a random string vs custom password makes no difference. The whole point of unique and strong password is so that a poorly encrypted service does not compromise your properly encrypted service. The scenario where my password is unencrypted is irrelevant, because only the salted hashed password matters. And because of the hash, leaking unencrypted passwords does not make the hashed ones easier to guess.
The whole issue with a manager isn’t that its bad, its that it puts everything under the one basket, even if its a hella strong basket. If you want to change my mind, you need to show the pros outweigh the cons. Straight up assuming that not using a manager somehow means anytime I have my password compromised equals everything else is compromised is not convincing, its circular reasoning.
Ignoring the fact that I’m explaining how hash works and not giving advice, if we want to be technical then yes only a slight change does make targeted attack easier. At that point password will only provide so much security, if you want to truely be safe, grade separate your username and email.
Thanks for the chat too, have a nice day
Edit: grammar