Comment Re:Rethinking our approach (Score 1) 106
>
Well, it's not secure any more!
Tabilizer, do NOT use that password!
> Of course, you'll never be able to remember it. Which is why you store it in a password-keeper, encrypted with a strong passphrase (the only thing you do need to remember) and using a strong encryption algorithm like AES256.
That's the theory. The part I love is that you practically have to store all your passwords in the cloud to make this feasible for most people, which is its own can of worms.
In practice, weaker passwords coupled with TOTP tends to be a better solution, if you can persuade people to use TOTP. If your passwords are compromized, change them before your TOTP keys are, and vice versa.