7 ms·
I agree with you and will not be using this tool. but it does seem like a good tool for those that do not want to use a password manager. (better than nothing f
by StephenConnell 10y ago
I agree with you and will not be using this tool. but it does seem like a good tool for those that do not want to use a password manager. (better than nothing for sure)
The attacker would have to know that you are using this tool, and they would have to know what you input for the site name and your username/password. So basicly you have three passwords for each site.
- JulianMorrison 10y agoIt would appear to be cryptographically pretty much identically secure as using a single password on all sites, if someone knows who they are targeting and what website. And less secure than having two passwords, your regular one and your Super Sekrit one for Amazon and the bank.
- quonn 10y ago> It would appear to be cryptographically pretty much identically secure as using a single password on all sites How? If a single password is used then if any of the sites is untrustworthy or stores the password insecurely (for example as plain text) or if the connection can be intercepted or the server is hacked an attacker directly gets access to all other sites. With the derived password this is only the case if the derivation algorithm can be attacked/the master password can be recovered successfully. So it still seems to be an improvement over a shared password.
- whyever 10y ago> It would appear to be cryptographically pretty much identically secure as using a single password on all sites I don't think this is true. To brute force the master password, you need to know the password of one site.