3 ms·
I use a combination of a master password (12 chars, only known to me, not written down) and a seed to generate gibberish passwords for websites. In most cases,
by acron0 13y ago
I use a combination of a master password (12 chars, only known to me, not written down) and a seed to generate gibberish passwords for websites. In most cases, the seed is the service or website it's for ("netflix", "reddit.com"). So, in the case of "netflix" my app gave me "qnQTs0-QO-9osX-me4)M". The benefit being that the passwords aren't stored anywhere, and I can retrieve them by simply visiting my web app.
(I didn't just leak my Netflix password, btw ;)
- hucker 13y agoInteresting.. I hope the generator function is non reversible? I.e., if you know the password ("qnQTs0-QO-9osX-me4)M" in this case) and your policy, could you find the master password?
- icebraining 13y agoYou can use a cryptographic hash on it. It's how SuperGenPass works: http://supergenpass.com/ http://supergenpass.com/ (Personally, I use an homegrown script that runs outside the browser, but does something similar)
- mhaymo 13y agoAm I wrong to be turned off by the fact it uses MD5? Still far more secure than anything I could do in my head I suppose.
- nicwolff 13y agoYeah. I wrote the password-hash generator that SuperGenPass and most others credit as their inspiration, and I moved mine http://angel.net/~nic/passwd.current.html http://angel.net/~nic/passwd.current.html on to SHA-1 years ago.
- mhaymo 13y agoWas thinking about this as an alternative to existing password managers. The advantage is as you say your passwords aren't stored anywhere, even in encrypted form, and can be retrieved as long as you remember the master key and algorithm, but the disadvantage is that you're essentially sharing a poorly-salted hash of your master password with every service you log in to. I'm going to go for a password manager for now, simply based on my perception that they're widely used by people who know more about security than I do.