Everything filed here is a normal habit. Not one of them is a mistake on any other website you use.

Habits that do not travel The check afterwards

Three addresses for Mars Market, set down the way they arrived

marsautbk3di5cj75eh4dakjjrngddnjwqfdltbq2sy6cf7unzkd2bad.onion
marsautkudspgk6j23cxdtrk36ae4fpis2eoe7izu5y2rsksvmfji2ad.onion
marshjhtog245vzjzcicnmv2ci6yljibvdm4pngq5kmkfvcutppboxad.onion

They carry no name, no number and no order of preference. This site never opens them, so it has nothing to tell you about what any one of them is doing at this moment, and you will not find a light, a percentage or a date of checking anywhere on it.

Home Habits from signing in to things Assuming there is a reset

Habits from signing in to things ยท habit 20 of 40

Assuming there is a reset

Losing a password is not a serious event anywhere else. It costs two minutes and a mail message, which is why nobody treats the moment of creating one as important.

What it does everywhere else

The link at the bottom of every sign in form is one of the quiet successes of the modern web. It turned account loss from a disaster into an errand. Because it always works, memory stopped being load bearing, and people could finally be talked into passwords they could not remember. A great deal of good practice rests on that link existing.

What it does on this one

There is no mail behind this one, so no link can work. A recovery phrase or code shown once at registration is the whole account, and the screen showing it does not come back. Whatever you kept from that moment is what you have. Whatever you read past is gone, and it went quietly.

The habit

You do not write the credential down, because losing it has never once been permanent.

Why it is automatic

This habit was taught deliberately, which is what makes it hard to see. Every workplace poster and every induction said never write your password down, and the people who followed that advice were the ones doing it right. Anyone who now hesitates at the idea of paper is responding to instruction rather than to laziness.

The reset link then removed the last reason to keep a copy. If forgetting costs two minutes, remembering has no value worth paying for. That is why almost nobody can produce most of their own passwords, and why almost nobody has ever needed to.

There is a third piece. Registration is fast, and the recovery screen appears in the middle of it, between the form and the thing you actually came for. It arrives at the moment of least attention in the whole visit, when the reader is committed, slightly bored and expecting one more click.

What it actually does here

The screen showing the phrase appears once. It is not in a settings page afterwards, it is not resent, and it will not be shown again on request, because the site does not hold it in a form it could show. That is a deliberate property, and it is the same property that means nobody else can read it either.

Nothing behind the screen can restore it. There is no mail address to prove ownership with, no document to send, no queue to appeal to. Ownership of the account is entirely and only possession of that string.

Nobody credible claims otherwise. Anyone offering to recover a lost market account is describing a service that cannot exist, and the offer is aimed at people in the state that makes them easiest to persuade: they have just lost something and they will prove things about themselves to a stranger to get it back.

The loss is also silent and delayed. Nothing announces it at the time. The phrase is read past, the account works for as long as the session lasts, and the gap appears later, on another machine or after clearing something, when the credential is needed for the first time.

The screen that shows the phrase is the account. Everything after it is a session.

What the advice against paper was about

The instruction never to write a password down came from a specific setting: an office, a shared machine, and a note stuck to the monitor beside it. The threat was the person walking past the desk. Against that threat the advice was correct, and it stayed correct for as long as most password use happened at a desk somebody else could reach.

Paper kept away from the machine is a different object, with properties the advice never considered. It cannot be read remotely. It does not synchronise anywhere. It survives a wiped drive, a lost phone and a browser profile that got cleared. For a credential with no reset behind it, those are the properties that matter.

Copies, and where they are not

One copy is a single point of failure, so two in different places is the usual sensible arrangement. What matters more is where the copies are not. A note application that synchronises to a company account puts the phrase somewhere with its own recovery process and its own staff, which is the arrangement the account was built to avoid. A photograph puts it in whatever picture library the phone uploads to.

The same reasoning covers the generated password from the password shape page. Neither string can be rebuilt and neither can be reissued, so both want the same treatment, and the simplest arrangement is that they live in one place and get checked together.

What to do instead

The whole intervention takes about ninety seconds, during registration, on one screen that will not be offered again.

  1. Write the phrase on paper before clicking anything that moves the page on. Do it during the screen, not from memory afterwards.
  2. Make a second copy in a different place, so losing one is an inconvenience rather than the end of the account.
  3. Read it back against the screen character by character while it is still there. Transcription errors are the common failure and they are silent.
  4. Keep it away from anything that synchronises, which rules out most note applications and the phone camera.
  5. Store the password and the phrase together, since they fail the same way and neither can be reissued.
  6. Treat any offer to recover a lost account as aimed at somebody in exactly that situation.

How to notice you did it anyway

There is one honest test for this habit and it takes a minute. Try to produce the thing, now, without the browser helping.

What readers ask about this habit

Is writing it on paper really the recommendation

For a credential with nothing behind it, kept away from the machine, yes. The old advice was aimed at a note on a monitor in an office. Paper in a drawer answers a different threat, and answers it well.

What if the phrase is already lost

Then the account is lost, and the only thing left to decide is who to believe about it. Nobody can reissue it, so any offer to do so reads as an approach rather than help. That reasoning is on why none of this counts as a mistake.

Can a password manager hold it instead

It can, provided it is one you maintain deliberately and can still open after a machine is replaced. The failure to avoid is a copy that exists only inside one browser profile, which goes with the profile.

Everything on this site