Double blind password

been using this method for ages , works great .
using a password manager , but neither me nor the password manager knows the real password :smile:
i only use it for sensitive sites

so basically all you have to remember is password manager master password (which you have to remember anyway), and your unique "add on"

3 Likes

Nicely cryptic video. It's all about Pepper (cryptography) - Wikipedia

1 Like

Instant fail, he has a facebook account! :rofl:

just cause he has a fb account , doesn't make the method fail.

ps: i also got a kinda trolling feeling from your post, which i don't really appreciate :rofl:

Facebook Accounts Hacked with 2FA

Facebook accounts can still be hacked even when using a double-blind password strategy. Here are some reasons and precautions:

Phishing and Social Engineering: Hackers can trick users into revealing their login credentials through phishing emails or social engineering tactics. Always be cautious with unsolicited messages and links.

Malware: Malware can infect devices and steal login information. Regularly updating antivirus software and avoiding suspicious downloads can help mitigate this risk.

SIM Swapping: Hackers can take over a phone number by convincing a carrier to transfer it to a new SIM card. This can bypass 2FA if the hacker controls the phone number receiving the verification codes.

Compromised Password Managers: If a hacker gains access to a password manager, they might not be able to use the double-blind password directly, but they could exploit other vulnerabilities or use the stored passwords for other accounts.

Device Compromise: If a device is compromised, hackers might gain access to stored passwords or cookies. Regularly monitoring account activity and logging out of all devices can help prevent unauthorized access.

To protect your Facebook account, consider the following steps:

Use a reputable password manager and implement a double-blind password strategy.

Enable and regularly update two-factor authentication.

Monitor account activity and devices associated with your account.

Be cautious with links and messages from unknown or suspicious sources.

Regularly update your devices and use antivirus software to protect against malware.

These measures can enhance your security but do not guarantee complete protection against sophisticated attacks.

1 Like

that makes sense from AI lol

i didn't meant the method to make one "un-hackable" , it's merely another layer of security,specially if (a big if) one's password manager gets compromised

3 Likes

But the point of the video is to protect your accounts in the event that your password manager gets leaked or hacked. It's the classic "don't putting all your eggs in the same basket" tactic.

Very clever trick, simple but effective.

Whilst Zorin isn't a Mac:

https://forums.appleinsider.com/discussion/237259/a-critical-security-issue-in-1password-for-mac-left-credentials-vulnerable-to-attack

And uses the Cloud:

NordPass is apparently the number one option in 2025:

https://cybernews.com/best-password-managers/