frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

Open in hackernews

A safe way to keep your password on your PC (Goodguy Ernie Method)

2•Geordinator•1d ago
Hiya,

I just signed up a few minutes ago and, full disclosure. I'm not a hacker. Not even close. But I had what I think is a pretty clever idea and wanted to know what the experts thought. This will probably be my first and last post. I hope you like it.

I’ve always been told by security "experts" to never keep my password(s) on my computer. But what about this scenario?

I’m keeping an unencrypted .txt file on an unencrypted hard drive on a PC with no password, no firewall, and a router that’s still set to admin/admin.

The file (which is the only thing on my desktop) is called: “THIS DOCUMENT CONTAINS MY MASTER PASSWORD FOR MY PASSWORD MANAGER. PLEASE DON’T DO ANYTHING BAD, OKAY?”

Inside is a single string of characters. Could be 5,000, could be 1,000,000 depending on how secure I want to feel. Somewhere in that big mess is my actual password, an uninterrupted substring between 8 and 30 characters long.

To find it, I just Ctrl+F for a small string of digits I remember. It might be 4 to 8 characters long and is somewhere near my real password (before, after, beginning, end, whatever I choose). I know where to start and where to stop.

For example, pretend this is part of the full string: 4z4LGb3TVdkSWNQoL9!l&TZHHUBO6DFCU6!czZy0v@2G3R2Vs2JOX&ow)

My password is: WNQoL9!l&TZHHUBO6DFCU6!*czZy0v

I know to search for WNQo and stop when I hit @.

So, what do you think?

Is it safe to store my password like this on my PC?

Comments

rzzzwilson•1d ago
Only one password? The experts (I'm not one of them) tell you to have a different password for each account, online and offline. The point is you don't want one leaked password to compromise any other account. I have something like 200 online accounts and they all have different passwords.
JSR_FDED•1d ago
He is referring to his master password for his password manager.
beardyw•1d ago
In some ways worse, since the password manager is unlikely to lock after multiple tries. They typically use lots of cycles to encrypt and decrypt to slow down multiple attempts. Given a minimum and maximum password length you can calculate how many tries to be sure to get it, and half that is the average.
Agraillo•1d ago
I think you invented (or reinvented) a simplified password manager, or a plain-text password manager. A usual PM solves the task of managing by human memory unmanageable: plenty of passwords with variable complexities routing them all to a single one intended for the human. In your system you have your own version of the master password (prefix + suffix) that locks out your actual password (a single substring). There are obvious drawbacks compared to a general PM like a much lower space of possible variants or needing to manage this manually (like generating the file or choosing randomly your prefix and suffix). But there is at least one benefit, if you keep the system simple enough (while not making it simple in generating the sequences), no hidden vulnerability should waiting to happen

AI in SMB Manufacturing: What Worked and What Did Not

https://fredlybrand.com/2025/05/29/ai-in-manufacturing-what-worked-and-what-did-not/
1•flybrand•57s ago•0 comments

Cory Doctorow – PyCon 2025 keynote

https://www.youtube.com/watch?v=ydVmzg_SJLw
1•ddejohn•1m ago•0 comments

Show HN: Logtrees, a Blockchain Economic Model Producing UBI and Debt Reduction

1•logtrees•1m ago•0 comments

Show HN: ClickStack – open-source Datadog alternative by ClickHouse and HyperDX

https://github.com/hyperdxio/hyperdx
1•mikeshi42•1m ago•0 comments

Copper adds ROS2/Zenoh migration path to its deterministic Rust runtime

https://www.copper-robotics.com/whats-new/zenoh-and-ros2-support-landed
2•gbin•4m ago•0 comments

Local information disclosure in apport and systemd-coredump

https://www.openwall.com/lists/oss-security/2025/05/29/3
1•jwilk•5m ago•0 comments

DeepTeam: Penetration Testing for LLMs

1•jeffreyip•5m ago•0 comments

Use FLUX.1 Kontext to edit images with words

https://replicate.com/blog/flux-kontext
1•p_sekhar•7m ago•0 comments

Difficulties Choosing a Captcha Provider [video]

https://www.youtube.com/watch?v=SasXJwyKkMI
1•raybb•8m ago•0 comments

Top Tech Firms Hire North Korean Cyber Operatives

https://www.politico.com/news/2025/05/12/north-korea-remote-workers-us-tech-companies-00340208
1•michaelrkn•8m ago•0 comments

Indian News Agency is abusing YouTube copyright strikes as an extrotion tool

https://www.cnbctv18.com/india/why-indian-youtubers-are-fighting-back-anis-copyright-claims-19611031.htm
2•temphnaccount•9m ago•0 comments

Extracting video covers, thumbnails and previews with FFmpeg

https://tech-couch.com/post/extracting-video-covers-thumbnails-and-previews-with-ffmpeg
1•StreamingCat•10m ago•0 comments

The Case for Bridge Editors

https://www.nmccarty.com/p/bridge-editors
1•mailyk•12m ago•0 comments

Private equity kills companies and communities

https://www.theverge.com/decoder-podcast-with-nilay-patel/676106/bad-company-private-equity-megan-greenwell-book-interview
3•leotravis10•14m ago•0 comments

A new language inspired by Go

https://github.com/nature-lang/nature
3•hualaka•15m ago•1 comments

The Coming AI Revolution in Distributed Systems

https://zfhuang99.github.io/github%20copilot/formal%20verification/tla+/2025/05/24/ai-revolution-in-distributed-systems.html
1•todsacerdoti•16m ago•0 comments

Billions of AI Users?

https://manualdousuario.net/en/meta-ai-google-ai-overviews-billions-users/
2•rpgbr•16m ago•0 comments

Learning coordinated badminton skills for legged manipulators

https://www.science.org/doi/10.1126/scirobotics.adu3922
2•belter•17m ago•0 comments

Resonant Charge Transport Through Open-Shell Donor–Acceptor Macromolecules

https://pubs.acs.org/doi/10.1021/jacs.4c18150
1•PaulHoule•18m ago•0 comments

Network Intelligence Is Changing the Internet

https://open.spotify.com/episode/0As720pZpDU26cx9qNLK14
1•oavioklein•19m ago•0 comments

Use B4 for Kernel Contributions

https://www.marcusfolkesson.se/blog/use-b4-for-kernel-contributions/
1•jakogut•20m ago•0 comments

UF/IFAS scientists confirm hybrid termites established in Florida

https://news.ufl.edu/2025/05/termites/
1•pseudolus•20m ago•0 comments

Trump administration backtracks on Harvard foreign student policy

https://abcnews.go.com/US/graduation-day-harvards-lawyers-head-court-defend-foreign/story?id=122307706
8•belter•20m ago•0 comments

VA-based DOGE associate gets 'the boot' after publicly discussing his work

https://www.nextgov.com/people/2025/05/va-based-doge-associate-gets-boot-after-publicly-discussing-his-work/405636/
3•whalesalad•22m ago•0 comments

What's the Damage with Long Covid? Advanced Imaging Reveals Clues

https://www.tctmd.com/news/whats-damage-long-covid-advanced-imaging-reveals-clues
2•lentoutcry•22m ago•0 comments

The Tariffs Are Illegal

https://www.bloomberg.com/opinion/newsletters/2025-05-29/the-tariffs-are-illegal
17•ioblomov•23m ago•5 comments

Open-sourcing circuit tracing tools

https://www.anthropic.com/research/open-source-circuit-tracing
1•jlaneve•24m ago•0 comments

Anthropic's circuit tracer is now open source

https://github.com/safety-research/circuit-tracer
2•jlaneve•25m ago•0 comments

Quantum Computing and the Hidden Subgroup Problem

https://www.daniellowengrub.com/blog/2025/04/23/hidden-subgroup
1•lowdanie•25m ago•0 comments

The Anxiety on Top of the Anxiety

https://exhotmess.net/?p=238
1•mooreds•26m ago•0 comments