4 ms·
One idea for a deterministic password manager to avoid having to change the seed when a single site is compromised would be to give a simple counter to each sit
by benjaminjackman 9y ago
One idea for a deterministic password manager to avoid having to change the seed when a single site is compromised would be to give a simple counter to each site which is hashed with the domain name (or whatever is used to uniquely identify that site) as well the secret to produce a password. When that site is compromised or a password change is called for its counter is simply incremeneted by one.
That counter can be exposed publicly as well as likely a regularization mapping to coalesce variants in the domain name to a single value, having those are pretty worthless without the secret. So I think that just need to be kept secret and then everything else can be kept in dropbox or wherever.
Edit: I missed it on first glance but I see that this is referenced in the link you posted, so nevermind then.