4 ms·
Correct, there is no salt. A dictionary attack will uncover common passwords. It's crucial to pick a strong secret key. That's the price you pay for using a sta
by stepstep 12y ago
Correct, there is no salt. A dictionary attack will uncover common passwords. It's crucial to pick a strong secret key. That's the price you pay for using a stateless password manager.
However, the gigazillion rounds are not for nothing. That is the defense against brute force attacks, which could otherwise crack passwords even if they are random.
- deleted 12y ago[deleted]
- oe 12y agoWouldn't you then need to sync the randomly generated salt across browsers? That doesn't seem so stateless anymore.
- maninalift 12y agoyes, that's exactly what stepstep said
- spoiler 12y agoI have made a CLI stateless password manager for myself once (still use it, actually) and I generally "solved" the salt issue by providing the salt manually. Examples: syntax: gassy salt base [password length || 16] gassy spoiler news.ycombinator gassy email@personal.me home_email gassy name@ work.com 32 in the next step you're prompted for a password (with echo off). Also, it calculates a token based on the salt which determines in which way the password will be generated. I know it's not ideal, but it served me well so far! :-)