hperrin@lemmy.ca 1 week ago
It’s probably not safe if they use that for everything. Someone could match emails and password suffixes, then they’d only have four letters to brute force. So all it takes is two leaks that your friend is on and he’s at real risk.
Generally, this would be avoided by whatever site storing their passwords as hashes instead of in plain text, but you can’t rely on that.
They should just use a password manager.
SpongyAneurism@lemmy.frozeninferno.xyz 1 week ago
If they start using Keepass, we now know, their master password will be: kessSWydThIThBaPl!690720
I hope OP just constructed the core password as an example only.