4 ms·
This seems to me like a very clean solution, is there a Chrome extension version of something like this? I'd love to tap on a password field, enter my secret ke
by Kequc 9y ago
This seems to me like a very clean solution, is there a Chrome extension version of something like this? I'd love to tap on a password field, enter my secret key, and have it autofill based on the domain of the page.
- ryan-c 9y agoIf someone suspects such a solution is being used, they can attempt to crack the master password. Combined with the weakness of this not supporting forced password rotation or varying complexity requirements well, it's really not a good solution.
- Kequc 9y agoWhy would anyone suspect that? You're talking about what 1 in several million users? All you have to be is above the threshold of "easy to hack". I'd like to be referred to such a thing if there is one already.
- ryan-c 9y agoThe specific tool mentioned uses a trivial scheme. If I were trying to crack a large breach, I'd probably try running a few billion master passwords with that algorithm.
- jhasse 9y agoIf you master password is weak, I don't think that bcrypt/scrypt in my tool would help when a breach has happened.
- ryan-c 9y agoIt absolutely would.
- jhasse 9y agoCare to elaborate? As I can't salt the hashes the attacker can precompute all the passwords he wants to try. If that takes 1 minute, it will take 1 minute for a database with 1 billion passwords and 1 minute for a database with 2 passwords.
- ryan-c 9y agoYou could simply have people use their email address (or name) as a salt. Not great, but it would help significantly. Eight character random mixed alphanumeric password, hashed with say, sha256: crackable in hours with a GPU cracking rig. Eight character random mixed alphanumeric password, hashed with scrypt using aggressive settings: could take years or decades to crack. There is absolutely a large class of passwords that will be cracked if the hashing is fast, but not if it's hashed with a time and memory hard function. You can make an attackers job literally over a million times harder at minimal cost.
- jhasse 9y ago> You could simply have people use their email address (or name) as a salt. Not great, but it would help significantly. This wouldn't work, as the attacker should know both from the database. Anyway: If the user really wants, he can already add his email or name to one of the input fields. A salt is just another input to the hash function so this would be the same. > Eight character random mixed alphanumeric password, hashed with say, sha256: crackable in hours with a GPU cracking rig. Let's say by "several" you mean two. Then if 62^8 = 2 hours that means that: 62^12 = ~3374 years Meaning that a 12 character random mixed alphanumeric password would already take longer than the scrypt approach thanks to the way the exponential function works :) And to do it the other way around (let's say that "years or decades" is 20 years): 62^8 = 20 years 62^5 = ~44 minutes That's why I don't like to advertise with an "uncrackable hash function". In the end this might lead users to choose a shorter password, which is way worse! > scrypt using aggressive settings Keep in mind that if a breach happens, the database is also hashed. And salted! So the attacker would need to crack that first anyway.
- jhasse 9y agoThat would be a good idea! I haven't written a Chrome extension yet, but I'm planning to do an Android and iOS app next.