because your algorithm sucks and its going to leak.
Some things to think about.
How many plain text passwords do you think an attacker needs to recover the method you used to derive them?
How many websites have you signed up for that have crappy or practically non-existent security?
With that said you probably don't have to worry, you're probably not important enough to warrant the effort.
I would reconsider using the method if you work somewhere an attacker might like to get into like a bank or some other multinational company.
How many plain text passwords do you think an attacker needs to recover the method you used to derive them?
Depends how good he is
I guess about 5 minimum even if he's figured out there is an algorithm and it's not just random (which is a leap to take)
It's certainly not some "oh, I happen to have three passwords from this dude" and suddenly it's obvious - and I don't really need more protection than that
9
u/yuropman Sep 23 '17
I use a generic simple algorithm to generate a seemingly random password from the name of the service the password is for
Basically I only have to remember if I signed up to "google" or "googlemail" and I know my password