3 ms·
An idea I had a while back - Build browser add-ons and a javascript site that performs N hashes of your master passphrase (high entropy) concatenated to the we
by TTPrograms 12y ago
An idea I had a while back -
Build browser add-ons and a javascript site that performs N hashes of your master passphrase (high entropy) concatenated to the website domain (google, ebay, etc.). Set that hashed password to be your password on each website. Then when you use a computer you enter the master password and it generates all the domain-specific passwords. If that website is breached only the specific password is released. Even if someone knows you're using this scheme you can make it arbitrarily difficult for them to break it and get the master password by making N arbitrarily large.
This way you could use one master password to procedurally generate all of your passwords from any computer without relying on cloud/storage while still keeping them relatively independent. It's sort of weak to rainbow tables, but you could make N large enough and use a high enough entropy password that this would be a negligible threat I think.
Thoughts?
- zepolen 12y agoChanging the master password will be a problem because you will have to update every site your have an account on.
- TTPrograms 12y agoYeah, that's kind of annoying. You could probably get autofill working reasonably decently, but it wouldn't be easy.