4 ms·
Please try 1Password or LastPass before you shoot yourself in the foot with something so unjustifiably insecure and functionally-hobbled as this. You'll see tho
by yetanotherjosh 7y ago
Please try 1Password or LastPass before you shoot yourself in the foot with something so unjustifiably insecure and functionally-hobbled as this. You'll see those apps are no hassle at all, this stateless approach really doesn't gain you anything but does cost you a lot.
What are the upsides to a stateless approach? Convenience/simplicity? When you look at the guessing game you have to play to get the right login with this, or the eventual personal state management you'll need to track exceptions, it's certainly not simpler in practice. Price? LastPass is free for personal use. Works offline? So do LastPass/1Password so long as you set them up first. AFAIK there are literally no upsides to this.
What are the downsides? Review this thread, all the big ones have been mentioned and there are more:
- Master password cannot be changed
- If master password is compromised, all your passwords are compromised, regardless of device. (For proper password managers, master password gets access only on the physical devices on which it's been synchronized and you can revoke a stolen vault's online authorization remotely.)
- Rotating a compromised password requires remembering you did it, or a guessing game to find the right iteration of a counter variable.
- Master password must be typed in full every time to get a site password. This will encourage you to have a short master password.
- Doesn't autofill login forms for you, requires copy/tab/paste.
- Master password is typed into a web browser for every single password. Browsers are generally a less secure runtime context than a native application.
- Doesn't remember the email/username you used for services.
- Exceptions to password rules imposed by websites (length/character requirements or exclusions) cannot be tracked
- It's not always clear what the name of the site/service is to use for the hash function inputs. Is is mybank.com or secure.login.mybank.com? Another guessing game.
- Many items above mean you will end up wanting some kind of state to track the stuff this doesn't deal with, and now you've implemented your own state solution which is surely far worse than what LastPass or 1Password have built.
One "upside" people might claim is that LastPass/1Password state servers can be hacked (LastPass was hacked once I think?). But this actually isn't nearly as bad as it sounds. If attackers get a bunch of (encrypted) vaults, they still have to brute force every vault individually. Furthermore, these providers have everything to lose in terms of reputation if they are hacked, so are financially incentivized to maintain the highest degree of system and software security. Compare that to this solution, which in every way trades aways security and has basically nil financial incentive for secure implementation.
I keep editing my post to add more reasons not to use this thing. Don't use it.