3 ms·
Nice one. I always found password managers a bit annoying to use, so this is a great alternative
by mingabunga 12y ago
Nice one. I always found password managers a bit annoying to use, so this is a great alternative
- thirsteh 12y agoThe idea is admirable, but it's a really bad alternative to having unique, random passwords for each site. With this, it's trivial to recover all other passwords if you know just one of them.
- unsignedint 12y agoAnd it won't work for some of sites that require periodical password changes... (It's annoying and ineffective, but I encounter some in my line of work...)
- aba_sababa 12y agoAs opposed to a password manager, where it's trivial to know every password within if you know the master password?
- thirsteh 12y agoWell, the difference is that if I compromise any of the sites you use, I now know all your passwords. If I compromise any of the sites you use when you use a password manager properly, I'll only know one password that'll be fairly useless to me.
- aba_sababa 12y agoCompromising one of these passwords does not at all mean that all the other passwords are compromised. You can't figure out the original master password from a hashed, compromised password.
- thirsteh 12y agoYes, you can. To understand why, compare: This: 'facebook' + 'mypassword' 'twitter' + 'mypassword' 'foursquare' + 'mypassword' Password manager with unique passwords: 'mSX32ZyKZXptY3E' '33RiKbc3n6sA6IY' '4kGzFtWDd0rnti6' All I have to do is figure out what you named the site that I compromised, then do exactly what I'd usually do to recover your password, and, voila, I can now access all sites you use it for. Compare this to the password manager example where each password has been generated at random--one password communicates no information whatsoever about the other.
- aba_sababa 12y agoOk, so you know that "facebook" is part of the original hash. Not following how you can also derive "mypassword" from it. If you have a good strong master password, rainbow tables won't be able to crack the hash.
- krapp 12y agoGetting the master password, itself, need not be trivial. Mine is in my head and in my wallet. And, even if you happen to stumble across one of my passwords, you can't derive any other passwords from it.
- err4nt 12y agoUnless you made some kind of post-generator transformation to them, like added the first character to the end of every generated password. If it gives you 'aJ2Y64f' and 'lLv8PV2S' and you decide to make those 'aJ2Y64fa' and 'lLv8PV2Sl' all of a sudden the ability to work backwards is lost, no?
- thirsteh 12y agoThat's just a matter of knowing the algorithm: If I know how you constructed the password, I know how to make candidate guesses. I don't even need to be able to work backwards; I just need to be able to reproduce one of your passwords (the same way you'd "reverse" a hash digest.) The best solution is randomness -- that's why secure random number generators are so fundamentally important in cryptography.