3 ms·
Great idea! And kudos for releasing it as free software. But I don't see how "nothing to intercept" is a security feature. That means an attacker can start bru
by rwinn 11y ago
Great idea! And kudos for releasing it as free software.
But I don't see how "nothing to intercept" is a security feature. That means an attacker can start brute forcing just knowing the victims name instead of having to obtain the encrypted files first.
- nikital 11y agoAccording to https://ssl.masterpasswordapp.com/algorithm.html https://ssl.masterpasswordapp.com/algorithm.html, Scrypt is used for key derivation. Scrypt is supposed to be very expensive to brute-force. Quote: The master key is a 64-byte secret key generated by performing expensive key derivation using the user's master password salted by their full name. It represents the user's global secret. The purpose of this process is to deter any attempts at brute-forcing a user's master password from a known site password. The key derivation is done using the scrypt algorithm, which guarantees that the process sufficiently time- and resource-consuming to make brute-forcing an infeasible attack. The key derivation is salted by the user's full name to prevent the generation of rainbow tables on the algorithm. This salt is not secret, and the user's full name is chosen because it is an input of sufficiently high entropy while being (hopefully) impossible to forget by the user