Hot take: using the same password with slight variations is still a BAD idea
I used to think adding a different number to the end of my go-to password for each site was genius. Then last year I got an alert that my email was found in the RockYou2024 leak and realized 15 of my accounts were all just variations of the same weak base. One breach gave hackers the pattern to guess the rest. Has anyone else had to rebuild their whole password system after thinking they had it figured out?
Gotta disagree with you on this one. If your base password is something totally random like "Jx7!mNp9" and you just swap the last two digits per site, that's way stronger than using "password1" with variations. I keep a core 16-character phrase with numbers and symbols, then tack on a site-specific 4-letter code at the end. The real issue is people using common words or phrases as their base, not the variation strategy itself.