2 ms·
Sorry for the late response. I lost track of this thread. > In practical use, how do you typically remember whether or not a site allows special characters or
by madmonk 5y ago
Sorry for the late response. I lost track of this thread.
> In practical use, how do you typically remember whether or not a site allows special characters or has a length requirement?
Good question, wish I had a good answer. That's one issue I've yet to solve for.
> Also do you ever have trouble remembering what you named a particular thing?
No, I base my names off the domain.
> Edit: on second thought, the use of only a numeric pin (with suggested length of 4) seems not good from a security perspective.
The pin length is unlimited. Also, the open nature of this approach allows you to pad site names however you like. For example, instead of using "amazon" choose to pad your names with 2 z's (not my method) as in "zzamazon".
> I’m curious why no true cryptographic hash algorithms were used?
There were certain requirements I had for the output that I couldn't guarantee from existing hashes, one was each for character only appearing once in the output.
> The other challenge I see is the integrity of the JS - would folks self-host this?
Yes. Users are also free to alter the algo to meet their own needs. A simple way to make it unique to you would be to reorder the characters in the 4 sets.
> please take these criticisms as genuine feedback
I am and I do appreciate it. Like I said, this is the first time I've publicly shared it and want any potential issues brought to my attention. I am not a security/crypto expert, barely a novice, and if I'm barking up the wrong tree with this approach I appreciate someone letting me know.