As a computer hobbyist, I often worry how good my passwords are. I've never seen anything to describe how important it is. This chart and the research is super. My hat off to HIVE!
@PerryM Ha! Thanks to password managers, all my passwords are 24 - 36 characters long and use all the combinations. Perhaps that's overkill.
@steve @PerryM that's good, especially since password-cracking algorithms are getting better.
@kainoa @steve @PerryM I use 1Password to generate (and store, of course) passwords, and I just keep it cranked up to whatever 60-something the maximum is in 1Password.

Some sites get angry about that.
@spiralmind @steve @PerryM 1Password has had some pretty bad data breaches, I'd recommend @bitwarden
@kainoa @steve @PerryM That sounds like LastPass, I'm not aware of any published 1P breaches.
Which Password Managers Have Been Hacked? – Best Reviews

Password managers can and have been hacked. Discover the biggest password managers hacks over the years and what to do to keep your passwords safe.

Best Password Managers Reviews
@kainoa @steve @PerryM Ah, that kind of vector, I was thinking more actual data exfiltration attacks. Bit of an ingenious headline on that page, and BitWarden should also be included for that level of vulnerability. https://flashpoint.io/blog/bitwarden-password-pilfering/
Bitwarden: The Curious (Use-)Case of Password Pilfering

While evaluating the behavior of Bitwarden, a popular password manager browser extension, Flashpoint’s Vulnerability Research team noticed that embedded iframes in a web page were handled in an atypical manner.

Flashpoint
@spiralmind @steve @PerryM fair enough. I wasn't aware bitwarden had a similar vector.
@kainoa @spiralmind @steve @PerryM There are two kinds of password managers. Those that were breached and the one that haven’t been breached yet.

Now, from the one that were breached. Did they loose your passwords or not?

The real bad breach is lastpass loosing payment information. I was a free user at the time so I’m unaffected. But that sure didn’t look good.
@matthieu_xyz @spiralmind @steve @PerryM the best password managers are the ones you host on your own machine. Far, FAR less chance of any breach.
@kainoa @spiralmind @steve @PerryM I need my passwords on too many devices to just use local keepass conveniently and I don’t trust myself as a sysadmin. But that would be the ideal thing to do yes.
@kainoa @matthieu_xyz @steve @PerryM In general I'm hoping passkeys will become a major thing where it makes sense, to replace passwords.