4 ms·
I like the site. It's uncluttered but seems to give just the right information in an appropriate level of detail. I've never really looked deeply at "password
by spokey 16y ago
I like the site. It's uncluttered but seems to give just the right information in an appropriate level of detail.
I've never really looked deeply at "password keeper" applications before (I think because Firefox seems to a reasonably good job of it), but your approach seems like a good one. I think if I tried hard enough I might be able to come up with a JavaScript-based attack vector to steal the browser's key, but I suppose that would be a lot of work for relatively little payoff (unless they've already stolen your database and are now looking for decryption keys).
I'm curious about your business model. Do you intend to make money from this? How?
- PawelDecowski 16y agoThanks! I hadn't looked at password managers before I built PassKey. I tend to use at least 3 computers on a daily basis and with PassKey (unlike browser built-in password managers) I can sign in to web apps from any machine (just need to get the bookmark). I don't think it's possible to remotely steal the encryption key as JavaScript doesn't have access to browser's bookmarks. Don't have a business model at the moment. It was a hobby project.
- spokey 16y ago> I don't think it's possible to remotely steal the encryption key as JavaScript doesn't have access to browser's bookmarks. I think a trusted site might be able to read the bookmark URL from the history object, but that seems to be sandboxed in general and might not contain javascript: links in the first place. If you were more clever with JavaScript than I am you might be able to do something like (1) pop open the current page in a new window to hide what you're about to do from the user, (2) invoke history.back() in the "parent" window, and (3) read the URL from window.location