2 ms·
> Any password based upon any dictionary word, even with a few extra bits tacked on like this approach suggests, is incredibly weak in the face of a JackTheRipp
by the_dave_santos 8y ago
> Any password based upon any dictionary word, even with a few extra bits tacked on like this approach suggests, is incredibly weak in the face of a JackTheRipper or HashCat attack. The scheme proposed here would fall quickly from a leak of the password hashes to a HashCat GPU dictionary attack.
You don't get the point of making it's unique. Even if the password is shown because of the advanced bruteforcing, the password can't be used to other services. Hackers will try the password to other services and when it's not working, it's going to ignore it and just try another password.
It's very unlikely that the hackers will try to guess how to reconstruct your original password from the one that he already has.
> .. a weak password being reused ..
The password is not re-used, it's unique for each website.
> Which is much less likely...
Again, you should trust the manager. You should trust the software where you install the manager. and on and on..
What worst is that probably people will use again a weak password for the manager thinking that it's safe.