Impossible passwords

April 23, 2008 7:50am

I wrote about the dilemma of passwords here: they must be impossible to remember, change frequently and never be written down. Now a kind fellow called Sean Gilbertson has sent me a pamphlet on his “Cryptogic” system. He suggests combining a fixed password section (eg TimFT) with a variable password. For instance an Amazon password might be 3TimFT3 because Amazon has three syllables and three vowels, while an eBay password would be 2TimFT2 because eBay has two syllables and two vowels. Pick your own simple rule for deriving a variable password.

It’s a nice enough system, and does deal with the important problem of using different passwords for different sites - which was the original question! Still doesn’t help much with the requirement to change passwords constantly, alas…