3 ms·
Considering this requires you to go back to a single source to retrieve your passwords, I fail to see what this offers over tools such as 1password. I am aware
by bluetooth 13y ago
Considering this requires you to go back to a single source to retrieve your passwords, I fail to see what this offers over tools such as 1password. I am aware that passwords are not actually being stored anywhere, but ultimately you are doing the same thing: copy and pasting. 1password with a sufficiently strong passphrase to protect the keychain (is it even called that?) is just as realistically impossible to crack.
- krapp 13y agoIt does occur to me though, that it could be turned into a browser plugin. I'd have no idea whether that would be an improvement over anything, though. Either way, it is an interesting thing. And just to play devil's advocate, there is the possibility that someone hosting this code theoretically could add an event handler to surreptitiously send them the content of the text fields by ajax, so there is the issue of implicitly trusting the host even if the passwords aren't stored anywhere.
- gtrubetskoy 13y agoAgreed. And given that my blog is not SSL, I wouldn't trust this particular implementation at all. But the point is that you can have your passwords without ever saving anything on disk. Even if you don't have 'net access, you could regenerate your passwords by having access to any SHA implementation, the code to do this is trivial.
- cynwoody 13y agoSo, host a known-safe copy of the code somewhere in the cloud with https access (e.g., one of your appspot apps). Then you'll know where to find it whenever you need to regenerate a password. Of course, you'll still need to trust that the machine you are using isn't logging your keystrokes. You face that problem in any case, but it's worse if all your passwords are exposed instead of only one or two. You probably should have two or three pass-phrases. E.g, one for banking and brokerage, one for other business use, and a third for fora, social networking, etc.
- intendedeffect 13y agoI use a similar scheme, and one definite advantage has been being able to access my passwords anywhere, on any device with a web browser, without worrying about synchronizing something to my phone, work computer, etc.