3 ms·
I used to use a deterministic password manager, but switched to bitwarden because I wanted to be able to rotate (some) passwords sometimes and never found a gre
by computerphage 6y ago
I used to use a deterministic password manager, but switched to bitwarden because I wanted to be able to rotate (some) passwords sometimes and never found a great solution using a DPM.
- jjoonathan 6y agoThat and dumb password requirements. I could never get my DPM to work more than ~80% of the time, so I had to haul around a supplementary password store anyway. Now I'm on bitwarden, too. I'd rather have a store that's on another piece of hardware with logging and rate-limiting. Unlike TFA, I'd consider this a strength, not a weakness, but right now the convenience price is extreme. U2F is good but it's still only a second factor right now and the migration story is abysmal. If they can extend it to serve as a first factor and add a migration story, it would be perfect.
- dheera 6y agoI just describe these "dumb password requirements" in a file that can be public, and have my DPM generate a password that fits those requirements. See my comment one level up with link.
- jjoonathan 6y agoYeah, which is a considerable inconvenience -- I know because I lived it -- all to achieve zero reduction in effective attack surface.
- dheera 6y agoThe file describing the requirements can be public. The requirements themselves are publicly stated. I'm less concerned about attack surface and more concerned about just not having to deal with the logistics of safely storing and syncing something sensitive that I could also easily lose or not have with me on a mobile device or freshly formatted, self-owned device far away from home. I also don't want to have to trust someone else to store it in the cloud for me, especially if that someone else is handing me a closed-source app to do that.
- jjoonathan 6y agoIn practice, bitwarden is a heck of a lot easier to get on a new device than a hash app(let) du jour + master password + execption list.
- fitblipper 6y agoI also ran into problems that caused me to abandon my DPM after a while. Unique password requirements pet store required storage which added back the sync/dependency on remote storage problem. I also wanted unique logins per site for added privacy/security. For me both of these requirements are more easily solved with a traditional password manager than a dpm.
- dheera 6y agoI wrote my own deterministic password manager that uses PBKDF2-HMAC-SHA256. I have a configuration file that defines the silly rules required by certain websites and also allows setting an "n" parameter that rotates the passwords. https://github.com/dheera/scripts/blob/master/passgen-params.json https://github.com/dheera/scripts/blob/master/passgen-params... The actual password generator: https://github.com/dheera/scripts/blob/master/passenter https://github.com/dheera/scripts/blob/master/passenter
- computerphage 6y agoDoes this work across multiple machines? (Phone + laptop?)
- dheera 6y agoYes, the whole idea is to not store state. You only need a master password and domain to generate your site-specific password, and possibly a few custom parameters describing password rules for weird sites.
- computerphage 6y agoI mean, it's great to "not store state" until you get to the last part of your comment: "possibly a few custom parameters describing password rules for weird sites", plus it also needs to include things like the number times you've rotated the password for each site. The point of my question was to ask how well your implementation manages state across multiple machines, but if your answer is "it doesn't need to" then I just don't see how you can satisfy my requirements.