5 ms·
I was not clear. This is the password for the password manager (e.g. 1Password/ lastpass master password). The password to rule them all. It should be extra se
by throw14082020 6y ago
I was not clear.
This is the password for the password manager (e.g. 1Password/ lastpass master password). The password to rule them all. It should be extra secure. I also have 2FA, but you must have heard of defense in depth.
Anyway, I want to be able to see the password and check for typos before entering it to unlock the vault. I don't want to retype the whole password in when I only mistyped 1 character.
When I say read, I don't mean screen reader. I mean read with my eyes, I didn't think this would be a sticking point.
- asutekku 6y agoHonestly, 90 digit password is only harder to type for you. It’s not more secure than only in theory when compared to, say, 20 digit password.
- throw14082020 6y agoI choose to have the highest level of security I can afford, of course there are diminishing returns with each layer of security. Im happy to see evidence that a long password is only secure "in theory", until then I will keep my strategy. I can type 100WPM and this password is based off ~uncommon words, so I'm not uncomfortable: I didn't complain about entering, I claimed the issue is 1 wrong character requiring typing the whole thing password. It only takes a few seconds, but it is frustrating to type the whole thing again (regardless of length). https://xkcd.com/936/ https://xkcd.com/936/
- masterofmisc 6y agoWell, considering the LastPass master password is stored as a 256bit string on the servers, your 90 character master password has 720 bits making it considerably more its that make up the hash thats stored on the servers! 1 ASCII character is 8 bits!
- throw14082020 6y agoYou don't understand encryption. The master password is not "stored as a 256bit string on the servers".
- masterofmisc 6y agoYeah it is!! LastPass stores our master password hashes as a SHA-256 bit key. All I was quipping at, was the fact that the password you enter in length is a whopping 720 bits! I find it funny that this bit length gets reduced to a hash which is only 256 bits in length. Your password has more entropy than the hash that gets produced from it.