My favourite “fuck around and find out” is to have your password actually be the same format that Hashcat uses for non UTF-16 passwords, $HEX(deafbeef)

RT I add commas to my password to fsck with CSV file it will eventually be dumped into after a breach.


Hashcat: the password is $HEX(c0ffee)
Hacker: Wow, an non utf-16 password that encodes to œætŷâ but it won’t accept it?!

