Choosing your password well
Published on 6 November 2016 · updated in 2020
maj: 2020

(This article was published in 2016 on pingoo.com, then lightly updated in 2020)
I'm not going to give you the usual advice you read here and there on the subject, but rather my own method for managing all my passwords on the Internet. I've tried everything, but for years now, I've stuck with the same strategy, which is, I think, pretty effective.
First thing, I decided not to use software to store my passwords, firstly because I no longer trust them, secondly because I don't like the idea that a single password gives access to all my other passwords. So I use my brain. Here's how.
- Use a different password for each site
That's the basics, don't use the same password everywhere, especially not, never. So make sure you have a password for each site. Now you're telling yourself that's too tedious, well no, not that much, I'll come back to it.
- An easy password for the crappy sites.
You can perfectly well keep a very simple and short password for the sites that pose no problem, for example for your pizza delivery site. Personally I use 3 different passwords: – One ultra-simple password that only I know, the same for all the crappy sites. Like Rabbit123. – A second ultra-simple password for all the crappy sites, that I share with friends. For example Netflix. Like Zucchini123. – A long and complex password based on a sentence that I adapt for each site. That's the most important one. I'll come to it right away. It's going to be something like 7Ilrflbnaamatuoe.
- How to come up with and remember an ultra-complicated password?
So here's my method, honestly effective. You just have to know by heart a silly sentence. Ideally, this sentence should be absurd or impossible to find. A quote you love, slightly modified, a short poem, or whatever. In my example, the sentence I have to know is: I really love fries but not as much as Easter unicorns. Silly, right? Well it's perfect.
What do we do with this sentence? Well we apply a certain number of rules to it, to turn it into a password. For example: – The first letters of each word: Irlfbnaamaeu. – We replace "as" with a symbol, or add a number, and so on. – We always end with a capital letter.
And there you have a nice quality password!
Now you need to know how to modify it slightly so it's different for each site. Several possibilities, for example take the first or last letter of the site, and insert it in the middle of your sentence. For more security I'll take the second letter of the site, so for the BNP site for example, it'll be the N. This letter I'll add right after the "I really love" of my sentence, which would give "I really love BNP fries but not as much as Easter unicorns." If I apply all my rules, that gives something like Ibnrlfbnaamaeu. Clean. For more security, you can choose several letters to add per site. You can even base it on something other than the site's name, for example the color of the logo, and instead of adding an n, I'll add the g from the "green" of BNP, or the "r" as the second letter of "green." Up to you to figure it out, it can be anything.
- And do you change your passwords often?
Yes, I have a list with all the names of the sites I have an account on, and I modify my sequence every year. If you change this password in 2020, well why not add 20 at the end, but that's too easy, so you can add just 2 or 0, which in my case would give Ibnrlfbnaamaeu2. Except that 2 is a bit lame at the end, so we'll put it at the very beginning: 2Ibnrlfbnaamaeu
- DAMMIT BUT YOUR THING IS SUPER TEDIOUS!!!
No. Try it, you'll see, it's less tedious to do than to read, plus there's something fun about coming up with the silly sentence at the start, and the whole "secret code" mechanism.
- I don't want to do it like you.
Well try other things! The important thing is to have different passwords for each site, that they be long, and to change them regularly. When possible, also enable two-factor authentication on the sites that offer it, it secures things even more.
By Paingout


