4 ms·
Do this instead https://spectre.app/ https://spectre.app/
by branon 4y ago
Do this instead https://spectre.app/ https://spectre.app/
- endisneigh 4y agooh that's cool. what I do is similar except simpler, much so.
- slivanes 4y agoHow does one handle password rotation requirements?
- encryptluks2 4y agoDoesn't that make your passwords predictable? If you use the same secret for every domain and now if an attacker figures out your one secret then they would be able to find out all your passwords.
- scarab92 4y agoHow is that different from any other scheme which uses a master password?
- encryptluks2 4y agoA master password is at least generating random passwords though and encrypting the passwords themselves. Let's say your master password gets compromised, but not the password database itself... then attackers would still have no way to access your other passwords. With the method being described, simply obtaining the "secret" makes other passwords known without even needing access to the password database itself.
- aix1 4y agoWhat do you when a generated password doesn't meet a web site's requirements (on length, character classes etc)?