Hacker News new | past | comments | ask | show | jobs | submit login

Password hints are simply multi-factor passwords with, when used as intended, really crappy entropy and often crappy back-end handling/storage.

If you must suffer them, use random values that you note locally and store safely (just like your password). (Or that you don't store at all, simply foregoing ever being able to use the password hints mechanism.)

And, adjust your level of trust in and comfort with the site, accordingly.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: