3 ms·
Since all this can be done client side, you don't really want/need to give your master password away. We built an app like this - its a chrome app and everythin
by shabda 14y ago
Since all this can be done client side, you don't really want/need to give your master password away. We built an app like this - its a chrome app and everything happens in your browser.
https://chrome.google.com/webstore/detail/password-generator/nnjgaeekiplalipomfgacalgehhcckbp https://chrome.google.com/webstore/detail/password-generator...
Source: https://github.com/agiliq/forgot-me-password https://github.com/agiliq/forgot-me-password
Its not as good as this as we use use MD5 to hash the generated passwords - reason being this was proof of concept, and built mostly for our use. If anyone wants to add bcrypt - pull request is gladly accepted.
- tinco 14y agoI ported scrypt to the browser for this sort of thing, you can find it here: https://github.com/d-snp/scrypt.js https://github.com/d-snp/scrypt.js Note that some other guy wrote the javascript which was made for Node, I merely changed some types so it would work in the browser, I actually have no idea if it is still secure :P Note btw, that as soon as tptacek wakes up he'll wack everyone around with his staff until we understand that we are fools for messing about with javascript security. And he should, because he would be right for it. This whole article should be banned, and I have flagged it, because it is a terrible idea and no one should be fooled into using this service.
- arnarbi 14y agoMD5 is a no go, SHA-256 would at least be better. I will look at your sorce though. Bcrypt might be too heavy in plain JS if chrome doesn't offer it as a part of its api. But I agree, this should be a browser extension, not a website. Edit: btw, found this: http://www.lorrin.org/blog/2011/06/15/a-fruitless-search-for-a-password-bookmarklet/ http://www.lorrin.org/blog/2011/06/15/a-fruitless-search-for...
- gst 14y agoI strongly recommend against using the Chrome app linked in the parent post. It uses a simple MD5 hash to derive the site-specific password from the master password, making it much easier for a site to use a brute-force approach to get the master password from the site-specific password. In addition, it seems that the code retrieves effective_tld_names.dat from Mozilla's server every time a password is hashed. Apart from performance considerations, this file is retrieved over plain HTTP giving adversaries another potential attack vector (by tampering with the version of effective_tld_names.dat sent to the browser).