Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
marcusfrex
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
9 ms
·
31.
▲
by
marcusfrex
9y ago
Transip.eu is solid. I have been working with them since 2014. And i have (and still) used Linode and DO too.
32.
▲
by
marcusfrex
10y ago
Actually i am not worried about bcrypt. I just wanted to use more enterprise level approved KDF other than individual work. But regarding criticizes probably there will be bcrypt, scrypt and argon2 implementations as options on the next rel
33.
▲
by
marcusfrex
10y ago
We are working on Enterprise version of it which will be having this option.
34.
▲
by
marcusfrex
10y ago
Yes, definitely you are right. And at the same time using various other methods "depending on the master key" makes it impossible for an accurate time and process estimation for brute-force attacks.
35.
▲
by
marcusfrex
10y ago
Actually installer compiled using Visual Studio 2015 on Windows 10 platform. Nothing specifically edited to the way of SHA1 but we fix it on next release. >> It is a very poor introduction to the application on the majority platform.
36.
▲
by
marcusfrex
10y ago
>> How does this handle situations where the generated password isn't accepted by the site? eg. Is too long, absolutely must have at least one symbol and one number, etc. You can specify password length if it gets too long and it
37.
▲
by
marcusfrex
10y ago
You are definitely right.
38.
▲
by
marcusfrex
10y ago
It's probably because different understanding of same terms. With "complexity" word we mean hardness to generate. It doesnt adds up more algorithms but character sets and hashing algorithms for PBKDF2 respectively.
39.
▲
by
marcusfrex
10y ago
Forgiva is not a key-derivation algorithm itself to compare with Argon2 but a combination way for various hashing and encryption algorithms along PBKDF2 "depending on master-key". So it's as much future-proof as master-key ge
40.
▲
by
marcusfrex
10y ago
Probably i should explain what i meant with "got outdated and requires a better version" sentence. It is a race and as stronger algorithms comes to life -and stronger attack methods invented against them-, others gets simply weake
41.
▲
by
marcusfrex
10y ago
>> What does password complexity have to do with the strength of the algorithm used to generate passwords? It is not the algorithm only but if you can look a little bit more closely, it is iteration count too. It uses 1.000 times and
42.
▲
by
marcusfrex
10y ago
>> 1) How is this safer than a standard password manager with TOTP-based 2FA? The second token, either produced by TOTP or something like a Yubikey, would guard against keyloggers, since the one-time code is useless after it has been
43.
▲
by
marcusfrex
10y ago
It generates underterministic way of calculation for a time-span of a successfull brute-force attack. Various hashing and encryption algorithms runs in different performance values. Thus, estimating for a CPU/GPU power or time range to
44.
▲
by
marcusfrex
10y ago
You are mistaken on one think: it is not just being it "theoretically" possible but likeliness -or hardness- of it. If the possibility of an attacker guessing my password at first try is one in a billion -or trillion- chance, then
45.
▲
by
marcusfrex
10y ago
>> Spamming the input with an array of whatever OpenSSL algorithms Ruby happens to make available, rather than using a memory hard KDF like scrypt, is a bad smell. Sooner or later key-derivation schemes gets outdated and requires a be
46.
▲
by
marcusfrex
10y ago
It's just for giving an idea about hardness. Of course GPU(s) or/and parallel processing far more better than that. We will put results with clusters and GPUs soon.
47.
▲
by
marcusfrex
10y ago
>> What does this even mean? Again "theoretically" all encryption methods prone to brute-force attacks. And plus, encrypted storages indirectly reveals "encryption passwords" on succeeded attacks.
48.
▲
by
marcusfrex
10y ago
Upcoming. And planning to make it available as Telegram Bot.
49.
▲
by
marcusfrex
10y ago
Theoretically stored passwords are not safe at all. Sooner or later they will get stolen if it is the case. Forgiva is actually big brother of kyle ( https://github.com/esurharun/kyle ) which has been at use for nearly 2
50.
▲
by
marcusfrex
10y ago
Same strategy but Forgiva doesn't just use one key derivation algorithm (such as PBKDF2) but plus various hashing and encryption algorithms too. And at the same time you may forget the options you used in Vault, it is not an option in
51.
▲
by
marcusfrex
10y ago
No. Why should it?
52.
▲
by
marcusfrex
10y ago
>> How does this compare, for example, to the KeePass family of pw-managers? It is a password manager too but with an alternative approach. >> "Fixes poor passwords, accessibility and storage problems with highly secure way
53.
▲
Show HN: Forgiva – Never saves your passwords but regenerates them
(forgiva.com)
97 points
by
marcusfrex
10y ago
|
96 comments
54.
▲
Unpatched Atlassian products still reign over a critical security flaw
(sceptive.com)
1 points
by
marcusfrex
12y ago
|
0 comments
55.
▲
Sceptive is looking for Jedi Knights
(sceptive.com)
1 points
by
marcusfrex
12y ago
|
0 comments
56.
▲
JBoss EAP/AS 5: Remote code execution
(sceptive.com)
1 points
by
marcusfrex
12y ago
|
0 comments
57.
▲
by
marcusfrex
12y ago
Hi, i'm the developer. :) One point to add for misunderstandings is that listing animal names and passwords mostly protects you from keyloggers. Even someone knows your master-key and all the details you use, it should monitor what you
58.
▲
Kyle: A password manager for paranoids.
(sceptive.com)
4 points
by
marcusfrex
12y ago
|
6 comments
59.
▲
How we hacked National Judiciary Informatics System of Turkey (UYAP) ...
(sceptive.com)
2 points
by
marcusfrex
12y ago
|
0 comments
60.
▲
Capsule 127 - Password cracker for cloud
(capsule127.com)
1 points
by
marcusfrex
13y ago
|
0 comments
More ›