# मज़बूत और अनोखे Passwords — डेवलपर्स के लिए 1Password और Secrets Hygiene

Source: https://www.geekswithgeeks.com/hi/secrets-hygiene/pm-strong-passwords

> लंबे random passwords या passphrases बनाएँ और उन्हें कभी दोहराएँ नहीं।

## लंबाई और अनोखापन जीतते हैं

लंबा random password अनुमान लगाना कठिन होता है, पर दोहराव ज़्यादा बड़ा ख़तरा है: एक साइट में सेंध लगे तो हमलावर वही email और password दूसरी साइटों पर आज़माते हैं ("credential stuffing")। Manager से हर account के लिए अलग password बनवाएँ।

## CLI से password बनाना

1Password CLI चुनी हुई लंबाई का password बना सकती है। कई random शब्दों वाले याद रखने योग्य passphrases उस एक password के लिए अच्छे हैं जो आपको टाइप करना पड़ता है, जैसे master password।

```bash
op item create --category=login --title="Example" \
  --generate-password=24,letters,digits,symbols
```

## Breaches जाँचें

1Password का Watchtower दोहराए, कमज़ोर या breach हुए passwords बताता है। सबसे पुराने और अहम accounts, जैसे email, banking और cloud consoles, पहले ठीक करें।

**Quiz:** अलग-अलग साइटों पर password दोहराना ख़तरनाक क्यों है?

- [ ] साइटें धीमी हो जाती हैं
- [x] एक साइट में breach से आपके बाक़ी accounts खुल जाते हैं
- [ ] Browsers इसे मना करते हैं
- [ ] यह ज़्यादा storage लेता है

*Answer:* एक साइट में breach से आपके बाक़ी accounts खुल जाते हैं. हमलावर leak हुए credentials दूसरी services पर आज़माते हैं, इसलिए हर account का अपना password हो।
