4 ms·
By "long sequence of words that are trivial for me to remember" I meant concatenation of secret questions, like in the bounty example: https://mprimi.github.io/
by mprime1 4y ago
By "long sequence of words that are trivial for me to remember" I meant concatenation of secret questions, like in the bounty example: https://mprimi.github.io/portable-secret/examples/bounty.html https://mprimi.github.io/portable-secret/examples/bounty.htm...
Unless I hit my head really hard, there's zero chance I will forget this passphrase.
- z3t4 4y agoKeys should be random. The hints make it too easy. Lets say there exist 100 male names and 100 female names, thats just 100*100 combinations for names part. You could make the key generation intentionally slow though to limit the crack speed.
- pritambaral 4y ago> You could make the key generation intentionally slow though to limit the crack speed. Am attacker keen enough to bruteforce can easily copy the ciphertext, IV, and salt to a tool that doesn't have a slowdown. Or, just modify the JS to remove the artificial slowdown.
- GeorgeHoneywood 4y agoPresumably they are using some KDF (Key derivation function) that is designed to be algorithmically slow in some way that you can't trivially sidestep.
- flavius29663 4y agoThis is an old problem: how to slow down the hashing. https://en.wikipedia.org/wiki/Bcrypt https://en.wikipedia.org/wiki/Bcrypt