{"id":167,"date":"2011-05-23T12:14:56","date_gmt":"2011-05-23T16:14:56","guid":{"rendered":"http:\/\/www.borg.org\/?p=167"},"modified":"2011-05-23T12:14:56","modified_gmt":"2011-05-23T16:14:56","slug":"write-down-your-passwords","status":"publish","type":"post","link":"https:\/\/www.borg.org\/?p=167","title":{"rendered":"Write Down Your Passwords"},"content":{"rendered":"<p>Recently someone pointed out that an Ubuntu mailing list will e-mail a forgotten password back to you.\u00a0 And that this is wrong.\u00a0 Well, I agree, but&#8230;<\/p>\n<p>I am never bothered when a mailing list sends me a plaintext password.<\/p>\n<p>But <strong>I<\/strong> do something Extremely Radical: I don&#8217;t reuse passwords.<\/p>\n<p>If a mailing list password of mine gets out it is only a mailing list  password.<\/p>\n<p>Reusing passwords is too scary. Somehow the idea of having just one (or  a small number) of keys to my life and casually handing out copies to  anyone who asks seems really stupid. How do I know what they are going  to do with it?<\/p>\n<p>Write down your passwords. Yup. Write them down. Keep a list, obscure  things a little in the list, but keep a list. Put it in your wallet,  keep an updated copy someplace else. If someone steals your wallet you  will probably notice it and you will be able to go change passwords  before the thief figures out your obscuring scheme.<\/p>\n<p>But when you reuse a password and one of the various sites is broken  into, first you won&#8217;t know it was broken into, second, even if you did  get notified&#8230;how would you ever know what other sites you used that  password on if you don&#8217;t keep a list?<\/p>\n<p>Yes, it is better for mail reflectors to not send out plaintext  passwords, but it wouldn&#8217;t matter much if you didn&#8217;t reuse passwords.<\/p>\n<p>It should bother you that a site is mailing back your real password, but sites are constantly doing things far  scarier than e-mailing a password the right person (such as letting  actual criminals get a copy). You should be far more bothered by the  password reuse that makes every breach have possibly unbounded consequences.<\/p>\n<p>Even if a site does a password reset and e-mails a temporary password,  that is also a risk. E-mailing the original password is only worse if it  is used elsewhere.<\/p>\n<p>Don&#8217;t reuse passwords.<\/p>\n<p>-kb, the Kent who thinks expiring passwords are stupid, too.<\/p>\n<p>\u00a92011 Kent Borg<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Recently someone pointed out that an Ubuntu mailing list will e-mail a forgotten password back to you.\u00a0 And that this is wrong.\u00a0 Well, I agree, but&#8230; I am never bothered when a mailing list sends me a plaintext password. But I do something Extremely Radical: I don&#8217;t reuse passwords. If a mailing list password of [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-167","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/www.borg.org\/index.php?rest_route=\/wp\/v2\/posts\/167","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.borg.org\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.borg.org\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.borg.org\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.borg.org\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=167"}],"version-history":[{"count":0,"href":"https:\/\/www.borg.org\/index.php?rest_route=\/wp\/v2\/posts\/167\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.borg.org\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=167"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.borg.org\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=167"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.borg.org\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=167"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}