4 ms·
PwdHash has serious usability issues: http://people.scs.carleton.ca/~paulv/papers/usenix06.pdf http://people.scs.carleton.ca/~paulv/papers/usenix06.pdf In part
by Gankro 11y ago
PwdHash has serious usability issues: http://people.scs.carleton.ca/~paulv/papers/usenix06.pdf http://people.scs.carleton.ca/~paulv/papers/usenix06.pdf
In particular, the fact that you type your password into the password field means that failing to invoke PwdHash means you either register with your raw password (making it worse than useless) or just leak your raw password with failed login attempts.
The password manager model (e.g. LastPass) is clearly superior in my opinion because the user doesn't know their passwords. Largely the only way to input your password is the correct way. Also determining the password for one site provides no information for others (assuming you're random generating the passwords). For PwdHash, if you crack the password you have a lot of information for breaking all the user's other accounts (because presumably they're reusing the same base password).