3 ms·
Interesting approach. What do you do if one of the passwords got leaked? What new password do you use then? If I knew one of your passwords, would you consider
by moasda 4y ago
Interesting approach. What do you do if one of the passwords got leaked? What new password do you use then?
If I knew one of your passwords, would you consider your system to be still secure?
- crugthew 4y agoThanks! Perfect security does not exist. It's the same as if the master password to a password manager app would be leaked, what then? You start from scratch and change the system. If a plain-text version would be leaked, that's the worst scenario. But in in most cases what could be leaked these days, is the hash. So you can change the password by modifying the context. For example, if you log in to "microsoft.com", you first used `ms` as the context string, so change it to `microsoft` or `m$`, or something else. You would still likely remember that quite easily. What this tries to solve is to be secure, unique for each account and not rely on any other third party.
- moasda 4y ago> not rely on any other third party That's the main advantage of your approach I think. And it works with all devices. A lot better than using the same password for several accounts, as many people do.