3 ms·
I agree that it's worse, but I'm not that surprised about the attention. I've seen people come up with this idea in multiple threads about password managers, so
by MrManatee 7y ago
I agree that it's worse, but I'm not that surprised about the attention. I've seen people come up with this idea in multiple threads about password managers, so there is clearly something appealing about it. Instead of seeing the traditional "stateful" model of password managers as additional strengthening (like I see it), some people see it as a weakness that we should get rid of. I don't understand why. Under what threat model does it make anything better?
I use a traditional password manager. If an attacker, perhaps with a hidden camera, managed to see me type my master password, then they would still need access to one of my devices before they can use it. And if I had any idea that my master password might be compromised, I would change it just in case. It's quick and easy.
With deterministically generated passwords, all of my passwords would be compromised the moment my master password is compromised. I might not even _have_ a complete list of all the passwords that I should now remember to change. And I wouldn't do it lightly, because it's far from quick and easy.
Also, if a single generated password leaks, then an attacker could use that to start brute-forcing my master password. It's nice and all that there is PBKDF2 to slow it down, but the situation is still worse than with a traditional password manager, where one leaked password doesn't reveal any information about the other passwords.