Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Well. That is an annoying password to have to change. Most of the I don’t care much because I just generate a new one and away I go.

The Microsoft password is one I couldn’t just copy paste from a password manager and now I have to change and relearn it.

Damnit.



Do you use MFA on your accounts? I guess if the attackers have the MFA seeds as well that wouldn't matter.


Is it a thick client app that you cannot use the password manager? Or just a web page that adds "onpaste=..." handlers to make life unnecessarily difficult? The latter can be "fixed" with some JS console magic.


Might be the password to login to the computer itself.


Yes. It’s my gaming machine log on. It’s just easier to know this password than to always have to find it.

I do not trust corporations, so I generally do not do things like biometrics and stuff.

I don’t completely understand how pins are more secure than my complex password either. That could be ignorance.


Worth noting that Microsoft lets you set up single-machine passwords (they call it a PIN) that you can use to access a user account on a machine without having the password for the associated MS account. That way you can have a secure (and changeable) MS account, but the single-machine PIN can be something you don't need to copy/paste.


Do you need a password on your gaming machine? What is your threat model?


Even if there’s nothing on the machine itself you care about, don’t forget about everything else it can talk to on your local network.


So the scenario is: somebody breaks into the house, sits down at the gaming PC, and is able to poke around the local network because the gaming PC has no login password?


I wouldn't say it's THE scenario, but it's A scenario.

There's a reason IEEE says it's best practice to give IoT devices a strong username and password and to segment them away from the rest of your network, right?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: