4 ms·
I started to created ypassword to manage many different password on many different websites. The main principle is mainly the same as yours. The formula is (mos
by yogsototh 14y ago
I started to created ypassword to manage many different password on many different websites. The main principle is mainly the same as yours. The formula is (mostly)
password = base64(sha(site,masterKey,number))
I added the number once one of my password was compromised and I wanted to update it. Using this number it is not so difficult to update to resolve most stupid limitation on password. Almost all my password are good without using this parameter.
Considering the compromised master key, if it is compromised, shouldn't you in the end replace all your password for any password storage system? Unless you are pretty sure your keychain datas weren't accessed?
Concerning KeepassX I believe this is more secure than the "generate using your master password + website". But for now I continue to use my generated password simply because I find it hard to synchronize all the passwords on all platform.
I don't like to use Dropbox or any "cloud" equivalent system to synchronize my keychain encrypted file.
Using the generation method you generally don't need to "remember" anything other than your login. And at most you have to remember login + length of the password + format (b64 or hexadecimal) + number. But this is generally not the case. And these data can be shared publicly with a reasonable risk that your password won't be cracked.
I haven't (as most people) found the best way to manage my password in the most secure way. But actually the generation scheme feels like a good enough system.