8 ms·
I'm the creator of visionary[0], a deterministic password generator that the article links to. When I thought of the idea (quite a while ago), I thought it was
by libeclipse 10y ago
I'm the creator of visionary[0], a deterministic password generator that the article links to. When I thought of the idea (quite a while ago), I thought it was a good idea, and I thought I was the first one there. I was wrong on both accounts.
The points that the article makes are right, and people should use conventional passwords over deterministic ones.
But I guess it appeals to a certain small subset of people. For some servers and things that I own I find myself using it sometimes: it turns a relatively strong password into a monster of a password.
Another useful use is that it's good at sharing passwords for things with friends, and for that, it's surprisingly handy.
For the average person however, the disadvantages and the things that could go wrong outweigh the advantages. Keepass is what you should be using.
[0] https://libeclipse.me/visionary/ https://libeclipse.me/visionary/
- tprynn 10y agoNot to be too pointed, but would you consider adding this disclaimer to your blog post and github repo? Hopefully that will inform potential users before using a system that could leave them less secure.
- ogrisel 10y agoFunny, I also implemented mine a while ago (mostly un-maintained but I still use it): https://pypi.python.org/pypi/virtualkeyring/ https://pypi.python.org/pypi/virtualkeyring/ I also thought I was clever and the first to do it ;) I have been thinking about adding support to keep some state info in a yaml file to deal with revocation and specific varying password policies (e.g. in a dropbox synced folder) but I was too lazy to implement it. If someone wants to do it please feel free to send a PR. The compromised master password issue is a real issue though.
- Nomentatus 10y agoUse a photo as the master password. It can't be confused with text.
- minitech 10y agoThis change seems kind of worrying: https://github.com/libeclipse/visionary/pull/40/files#r79336188 https://github.com/libeclipse/visionary/pull/40/files#r79336... The distribution of characters in “complex passwords” isn’t even?
- libeclipse 10y agoThat doesn't matter. I could just put a full stop at the end of the string and call it a complex password. The point of it was for sites that require symbols. The complex password doesn't add a meaningful amount of entropy to a sufficiently long normal password; a 32 character normal password already has log2(16^32) = 128 bits of entropy. We rely on the seed for security, the seed being the hash that scrypt spits out
- minitech 10y agoSo it’s way too complicated for that purpose, then.
- libeclipse 10y agoThat's not an argument. Keep in mind that entropy is a property of password generation, not the result of the generation.
- minitech 10y agoI mean, what do you want me to say? It is way too complicated. Why are you using a pre-shuffled character set and getting a permutation of it by index when the index is always extremely low compared to the number of permutations just to get some symbols in your password? Just base64-encode with a custom alphabet or something. I never said anything about entropy, either.