Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This is not a great password manager function; the reason is, losing your sha1sum password gives the attacker enough information to mount a very, very fast brute force attack against "strong_pass" as long as they know the "sitename".

A basic property of a password manager system should be that the loss of any password doesn't give attackers any information about other passwords; yours potentially concedes the "master secret" that animates all of them.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: