4 ms·
Mm, I want the option to * set generated pw length beyond 128 back * create groups of any unicode characters by myself and specifically black or whitelist the
by class4behavior 6y ago
Mm, I want the option to
* set generated pw length beyond 128 back
* create groups of any unicode characters by myself and specifically black or whitelist them for the pw generation,
* manage all keyboard shortcuts, both the local and global ones,
* auto-type with a global shortcut any chosen entry individually—but username, password, and otp in particular—so that I don't have to fix the seq and delays every time the website changes or I'm somewhere with slower internet.
The process would be:
either press a global shortcut to find an entry or pre-select it in the app, then use other global shortcuts to auto-type the attributes individually
* copy the password from the editing menu without revealing it,
* show the attributes in place of the notes
- ascar 6y ago> * set pw length beyond 128 back What's your usecase for such long passwords? 55 lower case ASCII characters (a-z) have over 258 bits of entropy. As an example, that's more than the key length of AES-256. If my limited understanding is correct that would mean it gives no additional brute-force resistance to use a password longer than 55 lower case characters for anything AES-256 encrypted (and thus also for anything weaker than AES-256). Similar logic should apply if the password gets hashed to 256 bits or less (e.g. SHA-256 or bcrypt with 192bits).
- class4behavior 6y agoDoes that matter? Some passwords are a long-term security solution so who knows what kind of flaws, advances, or use cases you may have to deal with. The limits should be whatever the software and hardware permits. Besides, a local password generator can be a convenient way to generate random strings for other uses as well.
- nabla9 6y agoYou gain nothing. The password is compressed into 256-bit key at the end so you gain nothing. Argon2 is used to derive the key, so all you need to worry is good password and maybe use keyfile if you want more security.
- class4behavior 6y agoYou're talking about the password for the password manager file, I think. I'm talking about the actual passwords you save. A password manager shouldn't be limiting or directing the user on the length of a passwords they need. If someone, for instance, wants a hex char string with more than 512 entropy, they need more than 128 chars.
- nabla9 6y agoKeePassXC 2.6.2 does not have 128-bit limit for passwords you save. I don't know if the previous versions had because I have not tested.
- tialaramex 6y ago> Does that matter? Yes. Right now what you're asking for is useless nonsense, and your provided motivation is basically "But I want it" which puts you slightly lower priority than the little girl who wants a pony 'cos at least she can articulate why.
- kokx 6y agoIt matters. It may trick people into thinking that longer = more secure. Which is only the case up to a certain extent. If you reach beyond 256 bits of entropy, there is no added security. No current system will use more than that. And going beyond that is not future proofing, because you're storing it in a current system, defeating any added entropy. I don't see good reasons why you would use a password generator embedded in a password manager for non-security purposes. Security purposes here are always more important than other uses. But if you do have a good example, feel free to prove me wrong.