3 ms·
Hi, This is inspired by the Password Hasher addon for Firefox. It will hash a password and generate unique strong password from the same input, varying by webs
by hirak99 14y ago
Hi,
This is inspired by the Password Hasher addon for Firefox. It will hash a password and generate unique strong password from the same input, varying by websites where it is called.
Reason I made it is 1) it has a custom salt, so a hacker cannot potentially bruteforce with this as a layer if you have set your 'unique master password', and 2) this is bookmarklet - no strong dependency on Firefox.
Sharing since some of you may find it useful too.
- david_shaw 14y agoThanks for making this. Although the best security would be a unique salt per account, that would make the portability of the app a lot tougher. Either way, this is a great way to prevent brute force attacks from determining a user's password, as well as preventing a serious incident should a website store credentials in plain text, then get compromised. Of course, in a perfect world, everyone should be using unique, random passwords for each account they have on the Internet... but this is a great way to protect people that are using relatively insecure passwords across the board. I'd suggest allowing custom salts so that users can enter their bookmarklet on other browsers, enter their "custom salt," and be able to get additional randomness. If this were to catch on, we wouldn't want people adding the salt to cracking tools etc (although that would be a lot more work/processing power on their part). Sorry this was long winded. Cool idea, nice implementation!
- hirak99 14y agoThanks for the comment. Not sure if I followed the custom salt part - unless it is already implemented at the bottom of the page, where I call the salt as master password in the custom bookmarklet. Would love to know your thoughts in case you meant something else.