The password you will not remember
There is no forgot password link here, and no address to write to. That fact pushes almost everybody toward a weaker password than they would otherwise pick, which is precisely the wrong response to it.
Back to minute 25Crown market addresses
crownm5jmtbhqnoxhexx7nyiygqgqofp3wnjyyfl74gziohqqy6oq5id.onioncrownrywlm7mnohkzntlir2tlhafq6tzphgqyag5cw5en7nprchfklad.onioncrownwpaimgizxylrvrh4u6acpvk4l757cfla7xs6zjki7tdjqbnv6qd.onionPublished exactly as supplied. Nothing on this site is monitored, tested or checked, so no address here is claimed to be working. What a copied address does and does not settle.
What actually happens here
You type a password twice and the form accepts it. There is no strength meter worth trusting, no policy nagging you, and no email confirmation. Whatever you typed is now the only thing standing between anybody and the account.
Then a thought arrives, usually a few seconds later. There is nothing here to recover this with. No link, no address, no support desk. And that thought produces a decision that feels prudent and is not.
The backwards reasoning, in full
It runs like this. If I cannot reset it, I must be able to remember it. If I must remember it, it has to be something I can hold in my head. Things I can hold in my head are short, meaningful and reused. Therefore my password here should be weaker than the one on my email account.
Every step follows from the last and the conclusion is wrong, because the first step contains an assumption nobody examined. You do not have to remember it. You have to be able to retrieve it. Those are different problems and the second one has a much better solution.
What to do instead
- Generate something long and meaningless. A manager will do it, or a handful of unrelated words strung together works fine if you are doing it by hand.
- Do not try to memorise it. That is not the job.
- Record it before you submit the form, not after. After means never, or it means a hurried note in the wrong place.
- Put it wherever you decided things go at minute 35, alongside the name from the previous page.
- Never reuse a password from anywhere else. The specific failure here is a password leaked from an unrelated site being tried against this account by somebody who has never heard of you.
- It is immune to guessing and to lists of leaked credentials, which is the attack that actually happens.
- It removes the pressure to reuse, which is where cross site damage comes from.
- Retrieval beats memory. Memory degrades on exactly the schedule you do not want.
- It only exists where you wrote it, so that place becomes the account.
- Writing it down feels wrong, because a generation of advice said not to. That advice was about sticky notes on office monitors.
- It shifts the whole problem into minute 35, which is the phase most people skip.
The stall is a person sitting at a password field trying to invent something both strong and memorable, which is a genuinely hard problem and an unnecessary one.
The failure that costs more happens silently. A memorable password gets chosen, the session moves on, and the weakness never announces itself. Nobody finds out their password was poor until the day it matters, and on this kind of account that day has no undo.
The third is a password written down after the fact, from memory, incorrectly. A recorded password that is wrong by one character is worse than no record, because it produces confident failed attempts and some systems count those.
Almost all of that two minutes is the writing down. The generation is instant and the deliberation should be zero.
On the absence of a reset link
It is worth understanding rather than resenting. A reset by email is a second door into the account, and a second door is exactly as strong as the mailbox it opens from. Places like this generally do not offer one because they do not want to hold the email, and because the door would become the weak point.
The consequence is real. There is no route back in through a support desk, and any page that offers you one is not what it claims to be. What replaces it is whatever recovery material the account gives you, which is the entire subject of the next phase.
You are not meant to remember it. Generate something long, write it down before you press submit, and never use it anywhere else.