4 ms·
> This is a very bad article even if it’s from someone reputable because they don’t explain why not at each step. Based on the context and how it's written, I
by craftinator 5y ago
> This is a very bad article even if it’s from someone reputable because they don’t explain why not at each step.
Based on the context and how it's written, I get the feeling he never intended it to be a full fledged article, just some tweets, then it grew organically from there. This was never an instructional piece of work.
- andrewmcwatters 5y agoI ended up tracking down the tweet thread and every single subthread I read had nothing meaningful to share. There were no insights to glean. I get this sense from a lot of people in security: smart enough to follow conventional advice, too uneducated to explain why. This password manager will almost certainly generate basically anything that will get hashed and salted in the end, so it’s all irrelevant as long as it’s basically not outputting passwords from exposed lists, and even then it’s still mostly irrelevant. I have never once heard of particular passwords being an issue in the industry outside of social engineering or common password lists. Completely irrelevant. It’s almost always data breaches. Never does it hit the news that 3.5 million password were cracked due to hackers reverse engineering the time the accounts were created against popular password managers. What nonsense. If you simply generated a password from /dev/urandom, it would have almost as much consequence as whatever they’re doing here. Edit: The source article referenced is the only thing meaningful, which explains the severity, everyone else commenting on it was a dope.
- duskwuff 5y agoYou have completely missed one of the the key points of the thread. Seeding the random number generator with the current time, measured in seconds, removes any element of randomness from the password generator. It makes it straightforward to produce a list of every password that this software has ever generated, or will generate in the future.
- andrewmcwatters 5y agoYeah, you’re right, I did, because the tweets were worse than worthless. Just link to the source article.