3 ms·
long random passwords that no user would create on their own Really? You see the ones my IronKey comes up with... I have about 140 of them. IMO anyone using a
by jrabone 13y ago
long random passwords that no user would create on their own
Really? You see the ones my IronKey comes up with... I have about 140 of them. IMO anyone using a password manager is pretty likely to be generating long, random passwords, or they're Not Doing It Right.
- deckar01 13y agoI am working on a replacement for password managers. Type a password, then [Ctrl] + double click the field to hash it. Even if the database is compromised, an attacker is unlikely to assume your plaintext password is a base64 hash. http://deckar01.github.io/SHA512JS/ http://deckar01.github.io/SHA512JS/
- deleted 13y ago[deleted]
- nickzoic 13y agoPersonally, I suspect the Right Way to do this is for W3C to standardize a special input field something like: <input type="passhash"/> which looks like a normal password entry field but automatically does some clever hashing on the client to create a per-site password. Of course, you can still get keylogged if you use a public computer or whatever.
- yeison 13y agoWell, the issue I'm alluding to here is the issue of avoiding collisions. Even the password generator will not create the same long random passwords precisely because they're random and long... So even with a password generator these are still long random passwords that no user would create on their own and therefore do not collide with the honeyword passwords. Also, the combination of password generator and honeyword is actually even more secure than either one; in a "Greater than the sum of its parts" kind of way.