Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I once did that for a site which I didn't want anyone to recover my password to and thus break the security. I -DID- write down the actual password.

Today, years later, I still can't login to the damn payroll site because there isn't a procedure for just completely resetting the password state of the account and it wouldn't let you log in without those extra things.

Since that point I have recorded every annoying split-password (that's what the 'security questions' actually are, a forced split in the single real password)...



Consider applying for YC's Winter 2027 batch! Applications are open till November 2.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: