Hacker Read top | best | new | newcomments | leaders | about | bookmarklet login

You should not trust anyone with your password.


sort by: page size:

I think you mean "You should not trust _anyone_ with your password".

Don't trust a 3rd party with my passwords.

don't trust anyone: even the people with whom you are attempting to verify your identity using a password.

Trusting someone else with your passwords is playing with fire.

Don't give those cunts your passwords.

Passwords are not "real" secrets. Don't put real secrets into password managers.

And this is why you should never, ever, choose your own password. You just aren’t as random as you think you are.

It remains true that no one should ever ask for your password.

Simply asking for my password is enough to make me distrust you forever.


You should never, ever, ever type a password on a public computer.

tl;dr - Don't give your password out to people that ask for it, otherwise people can do things with your account that you don't want them to do.

There is no novel technical vulnerability... Just another case of people being convinced to give up their passwords over the phone.


While I agree with the idea that you should never share your password, you're blaming the victim. Having read a few accounts of their exploits now, this company is manipulating these people.

People reuse passwords. The mere possibility of someone being able to see it is bad.

Password sharing is not a good idea, but sometimes or even often unavoidable.

Agreed. It's also a conceptually wrong thing to do. The password does not belong there.

Assuming you're more clever than whoever is cracking the password is a bad plan.

People trusting a third party for their passwords boggles my mind.

Please don't ever post your passwords, even in jest. The web is filled with crawlers that scrape passwords and add them to vast password dictionaries to be used in cracking.

This was the immediate and exact same thought I had the moment I read the first sentence of the post. Then I stopped reading. Clearly this was not an engineering decision, and passwords should be trusted to no one but competent engineers and cryptographers.

Yes, I know. It's certainly better to leak only the first eigth of your password than all of it, but it's still not something you should do.
next

Legal | privacy