4 ms·
I wanted to do something similar with a slightly different formula but got into major issues. I couldn't log in from any other computer without opening a termin
by bytesandbots 10y ago
I wanted to do something similar with a slightly different formula but got into major issues. I couldn't log in from any other computer without opening a terminal and typing code for two minutes. I couldn't use it from a mobile on the go. key logger was even more dangerous since now the attacker could learn all my passwords instead instead of just one.
- dheera 10y agoI don't run the computation on devices I don't own, in case my master password gets leaked by a keylogger. If I have to login to a non-sensitive site on someone else's machine, I compute the password on my phone and the type it in manually.
- bytesandbots 10y agoSounds ok. Thanks
- bytesandbots 10y agoTo add to that 4. You will need a clipboard everytime to copy paste which is not very safe Suggestion: Add a salt parameter to make it less deterministic, keep these salt in a personal database
- dheera 10y agoThe clipboard is indeed unsafe. I don't use the clipboard. On my Linux machines I use xte (apt-get install xautomation) to have my script enter the password after a delay of 3 seconds which is enough for me to switch windows and click on the password field where it needs to be entered. On phones I just type it in after looking at it, or compute on my computer and punch into my phone. I can memorize a 20-character string for a short time. In the future I might make a device to plug in via OTG cable, emulating a USB keyboard, to enter the password into phone apps. Another option for phones is key injection using /dev/uinput which is accessible if you run Cyanogenmod.
- Cyph0n 10y ago> I can memorize a 20-character string for a short time. Now I see why such a system works for you. Very few people can do that in case you didn't know.
- dfox 10y agoThere is probably some room for optimizing this by changing the used character set or using some rules for producing "pronounceable" strings.
- dheera 10y agoWe could use entropy from the PBKDF2 output to select English words from the OED. https://xkcd.com/936/ https://xkcd.com/936/
- andreareina 10y agoEnter Diceware: http://world.std.com/~reinhold/diceware.html http://world.std.com/~reinhold/diceware.html
- Spivak 10y agoThere is already a tool that can do this for you: pwgen. It's probably in your repositories but you can also get it here. https://sourceforge.net/projects/pwgen/ https://sourceforge.net/projects/pwgen/
- dfox 10y agoWhat I meant is that it would be interesting to plug such tool as an final encoding step of some variant of KDF(master, domain)