6 ms·
I tried 1Password, but there was a basic missing feature, you can't toggle reading the password. This was a deal breaker for me when I have a ~90 character pas
by throw14082020 6y ago
I tried 1Password, but there was a basic missing feature, you can't toggle reading the password.
This was a deal breaker for me when I have a ~90 character password (I often mistype one specific key everytime).
Bitwarden doesn't have this problem.
- Cthulhu_ 6y agoWhy would you type a 90 character password instead of copy / paste or have the manager fill it in? Also why 90 characters when 2FA would be the safer option? Or half that is already infeasibly long to brute force? Also what do you mean 'reading the password', like via a screen reader? I mean that would be pretty bad for accessibility, but if you mean displaying the password, my version has buttons for it (regular inline, and a popup with the password pasted large on the screen). I have so many questions.
- throw14082020 6y agoI was not clear. This is the password for the password manager (e.g. 1Password/ lastpass master password). The password to rule them all. It should be extra secure. I also have 2FA, but you must have heard of defense in depth. Anyway, I want to be able to see the password and check for typos before entering it to unlock the vault. I don't want to retype the whole password in when I only mistyped 1 character. When I say read, I don't mean screen reader. I mean read with my eyes, I didn't think this would be a sticking point.
- asutekku 6y agoHonestly, 90 digit password is only harder to type for you. It’s not more secure than only in theory when compared to, say, 20 digit password.
- throw14082020 6y agoI choose to have the highest level of security I can afford, of course there are diminishing returns with each layer of security. Im happy to see evidence that a long password is only secure "in theory", until then I will keep my strategy. I can type 100WPM and this password is based off ~uncommon words, so I'm not uncomfortable: I didn't complain about entering, I claimed the issue is 1 wrong character requiring typing the whole thing password. It only takes a few seconds, but it is frustrating to type the whole thing again (regardless of length). https://xkcd.com/936/ https://xkcd.com/936/
- masterofmisc 6y agoWell, considering the LastPass master password is stored as a 256bit string on the servers, your 90 character master password has 720 bits making it considerably more its that make up the hash thats stored on the servers! 1 ASCII character is 8 bits!
- throw14082020 6y agoYou don't understand encryption. The master password is not "stored as a 256bit string on the servers".
- masterofmisc 6y agoYeah it is!! LastPass stores our master password hashes as a SHA-256 bit key. All I was quipping at, was the fact that the password you enter in length is a whopping 720 bits! I find it funny that this bit length gets reduced to a hash which is only 256 bits in length. Your password has more entropy than the hash that gets produced from it.