Crown the first ninety minutes What this site is
The first ninety minutes /The account/The password you will not remember
25

The password you will not remember

Costs
Two minutes, including writing it down
The trap
Choosing memorable because there is no reset

There is no forgot password link here, and no address to write to. That fact pushes almost everybody toward a weaker password than they would otherwise pick, which is precisely the wrong response to it.

Back to minute 25

Crown market addresses

crownm5jmtbhqnoxhexx7nyiygqgqofp3wnjyyfl74gziohqqy6oq5id.onion
crownrywlm7mnohkzntlir2tlhafq6tzphgqyag5cw5en7nprchfklad.onion
crownwpaimgizxylrvrh4u6acpvk4l757cfla7xs6zjki7tdjqbnv6qd.onion

Published exactly as supplied. Nothing on this site is monitored, tested or checked, so no address here is claimed to be working. What a copied address does and does not settle.

What actually happens here

You type a password twice and the form accepts it. There is no strength meter worth trusting, no policy nagging you, and no email confirmation. Whatever you typed is now the only thing standing between anybody and the account.

Then a thought arrives, usually a few seconds later. There is nothing here to recover this with. No link, no address, no support desk. And that thought produces a decision that feels prudent and is not.

The backwards reasoning, in full

It runs like this. If I cannot reset it, I must be able to remember it. If I must remember it, it has to be something I can hold in my head. Things I can hold in my head are short, meaningful and reused. Therefore my password here should be weaker than the one on my email account.

Every step follows from the last and the conclusion is wrong, because the first step contains an assumption nobody examined. You do not have to remember it. You have to be able to retrieve it. Those are different problems and the second one has a much better solution.

What to do instead

  1. Generate something long and meaningless. A manager will do it, or a handful of unrelated words strung together works fine if you are doing it by hand.
  2. Do not try to memorise it. That is not the job.
  3. Record it before you submit the form, not after. After means never, or it means a hurried note in the wrong place.
  4. Put it wherever you decided things go at minute 35, alongside the name from the previous page.
  5. Never reuse a password from anywhere else. The specific failure here is a password leaked from an unrelated site being tried against this account by somebody who has never heard of you.
What a long recorded password buys
  • It is immune to guessing and to lists of leaked credentials, which is the attack that actually happens.
  • It removes the pressure to reuse, which is where cross site damage comes from.
  • Retrieval beats memory. Memory degrades on exactly the schedule you do not want.
What it demands
  • It only exists where you wrote it, so that place becomes the account.
  • Writing it down feels wrong, because a generation of advice said not to. That advice was about sticky notes on office monitors.
  • It shifts the whole problem into minute 35, which is the phase most people skip.
Where people stall

The stall is a person sitting at a password field trying to invent something both strong and memorable, which is a genuinely hard problem and an unnecessary one.

The failure that costs more happens silently. A memorable password gets chosen, the session moves on, and the weakness never announces itself. Nobody finds out their password was poor until the day it matters, and on this kind of account that day has no undo.

The third is a password written down after the fact, from memory, incorrectly. A recorded password that is wrong by one character is worse than no record, because it produces confident failed attempts and some systems count those.

How long this really takes
What people expectFifteen seconds, it is a password box
What it usually costsTwo minutes, including recording it properly

Almost all of that two minutes is the writing down. The generation is instant and the deliberation should be zero.

On the absence of a reset link

It is worth understanding rather than resenting. A reset by email is a second door into the account, and a second door is exactly as strong as the mailbox it opens from. Places like this generally do not offer one because they do not want to hold the email, and because the door would become the weak point.

The consequence is real. There is no route back in through a support desk, and any page that offers you one is not what it claims to be. What replaces it is whatever recovery material the account gives you, which is the entire subject of the next phase.

In one line

You are not meant to remember it. Generate something long, write it down before you press submit, and never use it anywhere else.