5 ms·
https://github.com/burrows-labs/pz https://github.com/burrows-labs/pz 68 loc
by burrows 11y ago
https://github.com/burrows-labs/pz https://github.com/burrows-labs/pz
68 loc
- striking 11y agoNice work! This is a very neat spin on the idea. I'll definitely give this one a try. edit: although, what happens if the dictionary is changed? It's the same on all Macs, but what about trying the same script on Linux?
- dchest 11y agoThe dictionary is only used once to generate master password. Then it derives site-specific keys with PBKDF2 from it. You can skip pz-master and use your own master password, but make sure it has enough entropy. @burrows: I think there's modulo bias here: https://github.com/burrows-labs/pz/blob/master/pz-master#L11 https://github.com/burrows-labs/pz/blob/master/pz-master#L11 It probably doesn't matter much, but the displayed entropy estimate won't be exact.
- burrows 11y agoYou're right; thanks.
- tyho 11y agoWhat if you need to change the password, store gmail.com.1? how do you remember which one you are on?
- dchest 11y agoIndeed, that's the reason I stopped using my own password generator and switched to password manager. (Also, sometimes I can't remember my username, so password manager is more helpful.)
- ariabuckles 11y agoNice! I also wrote my own stateless password manager: https://www.npmjs.com/package/viridium https://www.npmjs.com/package/viridium It handles changing a password by keeping a file of the salts, which is theoretically safe to post to a public github (mine's in my dotfiles repo, though it's a private bitbucket repo)