3 ms·
Software security is an engineering problem. If your threat model includes the attacker knowing how you generate your passwords (and it probably should for most
by peri 12y ago
Software security is an engineering problem. If your threat model includes the attacker knowing how you generate your passwords (and it probably should for most companies — insiders and disgruntled staff are a big risk), this scheme may not be significantly better than using 1password or a similar password safe on a device you know you/your employees will always have on them. That's not to say you're wrong, it's just that you're making trade offs here like in any other engineering problem.