← Back to context

Comment by zelphirkalt

2 months ago

You mean when using "sign in with" and then using a shitty password for your social media account?

If you use e-mail and password with a good password manager, that runs locally on your device and generate good random passwords, it is unlikely you will end up on haveibeenpwned, and even if one website does shit, the blast radius is only one account on one website.

You'll still have your e-mail address exposed, which you may not want if it is to some random porn site. Moreover, password managers do not work if you use multiple devices for log in, which most people actually do.

  • I use my password manager across multiple devices daily.

    Apparently it has not been working without me noticing it?

    • I assume they're thinking about the 'offline' style where one would shuffle a database file and probably resolve conflicts. There's an app/extensions nowadays, man!

      I don't even bother with a VPN, just occasionally push a 'sync' button on the roaming devices [when they return to LAN]. DB transactions [new credentials] averages ~0 per month... but there's plenty of capacity. Works extremely well.

      3 replies →

  • If you decide to visit such awful sites then the least you could do is not use primary email for this.

    I don't think it makes sense to even have a "primary email". I've completely separated work, shopping, banking, gaming etc mailboxes.

    Also how do password managers not work? Bitwarden syncs instantly across devices just fine.