2 ms·
No! This is bad from a security perspective based on entropy. Passwords generated here still have the exact same entropy as the input secret. In fact, you migh
by timvisee 4y ago
No! This is bad from a security perspective based on entropy.
Passwords generated here still have the exact same entropy as the input secret. In fact, you might even decrease entropy based on the length selected.
Entering a website, username and length doesn't increase the actual entropy, because you should consider these as known.
If users go about and use the same (basic) secret, which I imagine is a common practice, all their hashed generated passwords can be considered the same.
Users must ideally choose a different secret for every account, in which case a tool like this becomes obsolete.
Doing a large number of hash rounds has zero effect on actual security here.
What to do then? Generate a true random password for each instance. You can store those in a proper password manager.
- mistercow 4y agoI agree that this is a bad scheme, but I think the hash rounds do serve a purpose, which is to protect from sites with no/weak hashing. If a list of passwords gets leaked, it will be intractable to derive your secret from your password. But it gives you no good way to rotate an individual password if it gets leaked, and no good way to systematically rotate the secret if that gets leaked, since you’ll have to remember every site you used it on. Contrast that with a password manager, where rotating a single password is trivial, and rotating your entire vault is painful but straightforward.
- entropyneur 4y agoThere are cernainly pros and cons to deterministic password generators compared to password managers, but I don't see why there would be a difference entropy-wise. Weak master password to a password manager presents the exact same risk as a weak "secret key" in this app.
- timvisee 4y agoThe difference is that you'd also have to own the password store, rather than having to know about the hashing algorithm (which is open).
- dandanua 4y ago> Doing a large number of hash rounds has zero effect on actual security here The only way to derive the secret from a leaked password is to brute force possible secrets. The number of hash rounds increases the required computations. But even with only one round of hashing brute force will fail if the secret is sufficiently random (good luck brute forcing random 20 char strings). The only problems this scheme has (apart from a very weak secret) are password rotations and a leak of the main secret. Anyway, passwords should've died long time ago. Asymmetric private keys (derivable from secrets) should be a standard for user authentication.