Password Chart
passwordchart.com
passwordchart.com
If SuperGenPass were to pop its own window, calculate the site-specific complex password, then insert that into the form, it could probably be safe -- but would still need very careful design. (Once a bookmarklet starts interacting with a page, it might reveal its internal state to that page.)
And if you're really that worried about a new site, the mobile version can be saved to your local disk and opened in a separate tab, and then copy-paste the generated password into the site in question.
http://supergenpass.com/mobile/
Although this still requires that you trust supergenpass.com to not change the javascript it is serving you into something malicious.
It integrates well with Firefox & Safari, and will sync over wi-fi to an iPhone for an encrypted backup.
http://github.com/gfxmonk/supergenpass
Less convenient, but much less likely to leak your passwords via the browser...
In my mind, it's just a way to come up with "hard to guess, but easy to remember" passwords.
2. The cipher used is laughably weak. Given a sufficiently large output string (and sufficiently large is not large at all), it's trivial to brute-force the seed used to generate the substitution chart and determine the input password.
3. See my other comment on MITM attacks.
That happens if Cookies are disabled.
What I wanted to build was a password generator which takes a username and domain as inputs and spits out an pseudo-random passsword.
Something like: bgraves & ycombinator.com & salt = ybcgormabviensator#salt
The problem for me is that I use very hard to guess passwords, generated by my password database program (KeePass). Now I have no idea what those PW's are and rely solely on KeePass to keep track, which isn't available on my workplace PC (and, no, syncing my password DB between environments is not permitted.)
This site maybe what I was looking for, and it even looks like it's in JS to prevent most MitM attacks!
Thanks HN!!
The JS is delivered over cleartext HTTP. A MITM attack can substitute malicious JS code that will deliver your password to a third-party server.
If the purpose is to turn a short password into something more secure it is pointless. As tptacek is always saying; Sha1 is cheap. It is trivial to incorporate it into an attack :)
Your better off choosing a random long sentence as your password. Easier to remember and much more secure.
It isn't cryptosecure or anything, obviously, but it works well for my purposes. I've never been entirely comfortable with using someone else's web site or a password database (well, I use a password database at home, for example, but I have to have access to passwords remotely).
I built passwordchart.com four years ago after reading a comment on Slashdot. It got me thinking about building a simple form of a personal one time pad that could be regenerated via memorable phrase. The interactive password part is really just there to show how to use the chart.
Finally, for a data point for others wondering what a post on HN means for traffic, I normally get around 300 to 350 visitors per day. Yesterday there were 5623 visitors and so far today Google Analytics is reporting 1333 visitors.
My humble attempt (based on others work): http://python.ca/nas/tmp/pw.html
Edit: just to be clear, the page linked above needs to be hosted on a server you trust and served by something like SSL. Do not use it directly over HTTP and expect some security.
PasswordMaker uses your password and the website domain name to generate a unique password.
I can't imagine actually getting people to remember (and enter) strings like p?7J9JJ4M^E97J*J7J into a password field.
Or am I using it incorrectly?
Yeah, I don't think so somehow.
Isn't that ironic? Trying to make something secure by actually making it totally insecure?
(Before someone jumps, even it's JS it doesn't mean safe against MITM as someone can inject JS before it loads and send all keystrokes to another server)