5 ms·
This is a lovely idea, but in practice, has multiple problems. Firstly, if your password must be changed, maybe due to a data breach- you can't change it in yo
by emacsen 4y ago
This is a lovely idea, but in practice, has multiple problems.
Firstly, if your password must be changed, maybe due to a data breach- you can't change it in your password manager.
Secondly, different sites have different requirements on passwords- length, the presence of certain characters, etc.
Thirdly, while low probability, it is possible to have such a system compromised, and then passwords could be derived. This is no worse than a password vault, but a password vault can be changed easily.
A nice idea but not something to use in real life
- Asooka 4y agoYou could store a bit of metadata per password. Like an additional salt that you change every time you have to change the password, plus any requirements for generating it. Of course then it is using a kind of a vault.
- umvi 4y agoRight but that metadata (like password rules) is pretty much public information so it doesn't matter if an attacker gets it so it doesn't have to be as secure as a "vault".
- resoluteteeth 4y agoOnce you're assuming 1) you trust your master password or encryption key to provide sufficient security to generate passwords based on the domain and 2) you have a file you're synchronizing that contains metadata for each site like passwords changes and usernames well, guess what? Just go ahead and generate random passwords for each site, encrypt them with the master key, and store them in the metadata file! Since they're encrypted, the encrypted passwords are no longer more sensitive than the other metadata in the file and you just reinvented a normal password manager.
- umvi 4y agoThe biggest problem with password managers is that you become completely dependent on them (and therefore completely helpless without them) once you start using them. This scenario still allows you to remain decoupled from that dependency. You could print out a copy of your metadata to take with you on your trip to Europe without worrying that you'll be completely hosed if someone steals your phone/password manager.
- usrbinbash 4y ago> You could print out a copy of your metadata to take with you on your trip to Europe without worrying that you'll be completely hosed if someone steals your phone/password manager. I can take a copy of my pwd vault with me. I'm using pass, so the vault is a directory of files encrypted with a private key, which itself is encrypted with a strong passphrase. Even if I do end up losing that copy; What are the chances that someone breaks todays encryption standards, and does so before I notice the loss and simply change all my passwords?
- umvi 4y agoHow do you get into your accounts if you are on vacation and you lose the copy of your pwd vault?
- blamestross 4y agoI implemented a personal tool based on the same principle. I decided having a config was worthwhile and then you could just add a "version number" to the salt. Having a config provides the vulnerability of listing what sites you use, but let's you add things like a per-website salt.
- archi42 4y agoI would underestimate one critical advantage of your system: If the site changes their URL for some reason (depends on which components you use) you can just look up the old URL in your database. Without that, good luck figuring out that it was sea.customer-sso.auth.example.com/portal/login.jsp :)
- blamestross 4y agoThis happened when cbs rebranded to paramount
- blamestross 4y agoI also ended up making a DSL for making passwords compatible with arbitrary dumb password requirements.
- deleted 4y ago[deleted]
- umvi 4y agoIt has a few drawbacks but also some advantages (namely that is way more convenient than a traditional PM and also doesn't actually store any passwords)