Edit: It seems people don't understand what I mean... I just put some code here to better explain: https://github.com/w8rbt/dpg
Edit: It seems people don't understand what I mean... I just put some code here to better explain: https://github.com/w8rbt/dpg
One is really not that much more secure than the other particularly when dealing with online websites.
But yeah if the site gets hacked you have to pick and remember an iterated password (ie a next iteration) or regenerate a new master password.
Of course if you are really paranoid you can always generate a password with dice and write that password down somewhere in safe place (ie offline password generation).
password = hmac(url++nonce, master_key)
You then store url and nonce. it's no problem that this info is public as far as I know, but perhaps you could again encrypt both the URL and the Nonce using symmetric encryption using the master keyEvery time you need to change your password, (because it leaked), you simply generate a new nonce. You only store the nonce and the URL and this seems like a very secure scheme to me.
Cons: You can not change the master key after the fact, so make sure it's secure.
I'm not a cryptographer, so I'm probably missing something obvious
Edit:
We still need to solve the "password constraints" problem. I would say, we could add functions that given the password stored, deterministically creates a string from the password that adheres to some specific password scheme. For example, by using the password as a seed to a random number generator used to fuel traditional password generators like the one included in lastpass. The 'scheme' would also be stored next to the nonce and the url.
And if you end up using a database for storing your nonces and hashing schemes you'll end up with the same limitations and attack vectors the parent was complaining about.
You could argue that it makes offline attacks easier because many encrypted storage formats have a way to check if the decryption was successful or not but you could remove this feature if that was a problem for you. And at any rate using a strong enough passphrase would make this attack impractical in the first place. And being notified when you used a wrong passphrase is pretty useful IMO.
Is there a different solution?
I use this tool to generate the passwords: http://hackage.haskell.org/package/scat
For those corner cases you can have different password generators, for more complex constraints. But overall it's not a big hurdle.
With a password manager that randomly generates unique passwords, you don't have that problem, but you do have to synchronize the data.
the seed is just the seed, and will always be the seed. the master password can change and be supplemented by 2FA / other enhancement schemes.
(Nevermind that you can't change individual passwords or the master password at will with a deterministic scheme.)
I mean sure its not the most secure thing and yeah you have to remember which iteration you are on once the site has some sort of databreach or makes you change your password but it generally works pretty well.