Hi!
On Sun, May 15, 2016 at 03:34:07PM +0200, [email protected] wrote:
I'm not entirely convinced that a password generator is a better or
more secure approach. Some considerations to keep in mind:
* There is a limitation to what characters you can use for the "salt",
at least the way that script does it.
* It doesn't account for different password length limitations and
special character requirements that some services have. Now, these
requirements and limitations are stupid, but it's something we have to
deal with if we wish to use these services.
* It's not random. I don't know of a way to do this, but if someone
figured out a lot of your passwords and gained access to your script,
it might theoretically be possible to find patterns and crack your
"salt" that way. Of course, the possibility of such an attack is
pretty remote, and this method might be perfectly safe from such an
attack, but this approach is not very popular, so it hasn't had much
of a chance to be properly audited for such a vulnerability. I'm not
saying it's insecure, but we have no reason to believe that it's more
secure.
* This is the most important part, and the main reason I stopped using
this method: if any of your passwords is compromised and has to be
changed, like back when various servers were affected by the
"heartbleed" bug, you have to update all of your passwords to fit your
new "salt". With a regular password manager, this would only be
necessary if the password database itself were compromised. What's
more, with this method, you don't have a list of all the passwords you
need to change, so you need to continue to remember your old "salt"
just in case you missed something.
What do you think of pass? It generates a password using pwgen, and
stores the result in a gpg-encrypted file. You can change the length of
the passowrds, and specify if you want symbols or not.
It's basically just a script around gpg and git.
--
Khoi