3 ms·
Sounds like a good idea at first, but could also be a huge attack point.
by scrapcode 10y ago
Sounds like a good idea at first, but could also be a huge attack point.
- Bartweiss 10y agoThe "replicate" bit sounds deeply alarming - a password manager using social or learned rules just screams vulnerability. If you made me guess an attack, I'd picture someone paying for a server cluster or botnet to repeatedly assert super-restrictive rules, and then use their knowledge of those rules to guess the generated passwords. Allowing some basic rule-setting, though, sounds quite nice. Arbitrary restrictions will probably leave people setting bad passwords, but there are some very common flags like "must have a special character" or "can't have a special character" that it'd be convenient to access for these sites.