3 ms·
There's a new kid in town: https://www.ctrlc.hu/~stef/blog/posts/sphinx.html https://www.ctrlc.hu/~stef/blog/posts/sphinx.html pro: it has much stronger securi
by mstef 5y ago
There's a new kid in town: https://www.ctrlc.hu/~stef/blog/posts/sphinx.html https://www.ctrlc.hu/~stef/blog/posts/sphinx.html
pro: it has much stronger security guarantees than the rest, it's self-hosted, but you can use other peoples servers!
cons: there is no UI frontend for macs, and UI integration in browser could also be improved.
(i'm the author, ama)
- paulryanrogers 5y agoSo a derived password generator like SQRL and friends?
- seanw444 5y agoYeah this isn't a new concept. I personally like Lesspass.
- mstef 5y agothe thing is. sphinx is designed by people with outstanding crypto protocol design credentials, the guys who came up with hmac and hkdf cryptographic primitives. the nice thing about sphinx is that it comes with "information theoretic security" - a very strong guarantee, not sure how the competition stacks up against this though...
- mstef 5y agonot sure, by looking at the sqrl wikipedia page it's not immediately obvious how this works. but yeah, "derived password generator" sounds correct, with one important detail. the there is (almost) no state at the client, and there is a mandatory online component where part of the derivation happens.
- paulryanrogers 5y agoIs rotation supported? And if the main password is compromised doesn't that compromise all future derived passwords too? It also means an attacker needs only the main password and knowledge of which derived system one uses. They don't need a vault file as well.
- mstef 5y agowhat does rotation mean? you can change your passwords, both the "master" which i rather call input, and the output password as well. i mean you can have a new output password without changing your input password. and no although i can only guess what you mean with vaultfile, an attacker still needs access to the sphinx server, which has protections against bruteforce attacks.
- mstef 5y agoyou might want to read the whitepaper regarding bruteforce attacks: https://github.com/stef/pwdsphinx/blob/master/whitepaper.org#bruteforce-attacks-against-our-sphinx-implementation https://github.com/stef/pwdsphinx/blob/master/whitepaper.org...