3 ms·
The _prettyPrint [1] and _getPasswordTemplate [2] functions they use to get from the HMAC to the actual password seem to have a lot of issues: - _prettyPrint c
by ekiru 10y ago
The _prettyPrint [1] and _getPasswordTemplate [2] functions they use to get from the HMAC to the actual password seem to have a lot of issues:
- _prettyPrint calls into _getPasswordChar which will then take the character code modulo the length of the array of possible characters [3], which is usually going to be biased if the character code is not uniformly distributed between 0 (inclusive) and a multiple of the length (exclusive).
- It's even worse because the input to _prettyPrint is the HMAC encoded as a hexadecimal string. The impact of this depends on the size of the possible character array, but in several cases, some of the options can never be chosen and others will be chosen twice as often as others that can be chosen.
- Using the hex encoding also drastically reduces the number of possibilities for a given length even if that input was then used in a less flawed fashion.
- _getPasswordTemplate appears to treat a password with lowercase/uppercase letters as a series of alternating vowels and consonants (by appending 'vc' or 'VC' to the password template).
- It also generally seems to define "password containing X and Y char types" as "password containing X char type, then Y char type, then X, then Y, and so on".
[1]: https://github.com/lesspass/core/blob/master/lib/index.js#L82 https://github.com/lesspass/core/blob/master/lib/index.js#L8...
[2]: https://github.com/lesspass/core/blob/master/lib/index.js#L66 https://github.com/lesspass/core/blob/master/lib/index.js#L6...
[3]: https://github.com/lesspass/core/blob/master/lib/index.js#L117 https://github.com/lesspass/core/blob/master/lib/index.js#L1...