5 ms·
Someone should add a "Has my hashed password been broken?" and an opt-in notification when one's password is eventually revealed. Last person standing gets a p
by bahjoite 8y ago
Someone should add a "Has my hashed password been broken?" and an opt-in notification when one's password is eventually revealed.
Last person standing gets a prize.
- wepple 8y agoEveryone who uses a password manager would win
- y4mi 8y agoUsing a password manager doesn't make you immune to having your credentials leaked if a sites database is breached...
- Ajedi32 8y agoIt actually does, provided the passwords aren't stored in plaintext. Even something ridiculously weak like a SHA-1 hash isn't going to be cracked if the password is 16 characters long and completely random.
- ianseyer 8y agoprovided: - the passwords aren't stored in plaintext or any other compromised hashing mechanism - you autogenerated your password - your password manager does not get compromised saying "it actually does" is a bit of absolutist stretch...
- arghwhat 8y agoFurthermore, none of this is a side-effect of using a password manager. It just makes doing so more convenient.
- aidenn0 8y agoWithin a margin of error, zero people can remember 20 16-character random alphanumeric passwords. Therefore it is only possible using some sort of password manager, whether it be something like 1password or an old-fashioned notebook.
- majewsky 8y ago> Within a margin of error, [the value of a measure is] zero. Nitpick: Zero does not have a magnitude, so "a margin of error" is not remotely well-defined here.
- arghwhat 8y agoYou need to specify your margin of error. ± the full population of humans on Earth is "a margin of error". I may be an outlier, but I certainly remember 10+ 20-25 character random full-printable-ASCII passwords, some of which don't let a password manager handle them, others which I don't want to have in a manager. And then there's my password manager master password, which is close to 70 characters long. And I have shitty memory—I wouldn't be able to remember what happened more than a few days ago if my life depended on it.
- lightedman 8y ago"Even something ridiculously weak like a SHA-1 hash isn't going to be cracked if the password is 16 characters long and completely random." Uh, yea, about that - that's how we cracked 4chan Tripcodes. 16-character SHA-1 is dead in just a few seconds with a GPU and that was, what, a decade ago?
- wavemode 8y agoUh... he never said it did? Just that yours would be the last hash to be cracked.
- y4mi 8y agothen why would that password tresor user win, after his credentials were leaked by a database breach -- before other select people that weren't compromised but abstained from said software. Its generally incomprehensible to me why some people don't want to use password tresors -- its so much easier after all - but his argument was flawed.
- tambre 8y agoWhat's a password tresor? Did you mean password manager? Wiktionary tells me it means "treasure" in Catalan and Old French.
- dcuthbertson 8y agoIt also means "storehouse", so he probably means password manager.
- seele 8y agoI think he meant this: https://trezor.io/ https://trezor.io/ And more specifically: https://trezor.io/passwords/ https://trezor.io/passwords/
- BlackLotus89 8y agoTresor means safe in german so maybe he is a german that substituted the z in trezor
- y4mi 8y agoI meant password manager/safe. Sorry for that mix up.
- wepple 8y agoBecause parent said there would be a competition for whose password is cracked last. My 16 char fully randomized passwords will not be cracked, so I win, along with everyone else using a password manager?
- ythn 8y agoI still think algorithmic passwords are safer. I could get access to all of your passwords via a simple keylogger to scrape your manager's master password. There's no way you can get at mine because the master password is the algorithm in my brain. You could try to get 2-3 of my existing passwords and reverse engineer my algorithm, but in the words of Liam Neeson: "Good luck"
- tomschlick 8y agoAlso, 1Password has already integrated this into version 7 (in beta). It will let you know if any of your passwords are on HiBP
- xeromal 8y agoI'm still on 4, the non cloud version, so I probably don't get the fancy feature. :(
- Svenstaro 8y agoWell there's this https://spycloud.com/ https://spycloud.com/
- deleted 8y ago[deleted]