password = b64encode(hashlib.pbkdf2_hmac(
'sha256',
(master_password + '/' + domain).encode(),
b'',
100000 + n
)).decode()[0:16] + 'Aa$1'
master_password = some master password that you never write or store anywheredomain = domain name for the service in question, e.g. 'facebook.com'
n = the nth password being generated for the domain (typically 0)
The 'Aa$1' is to ensure satisfaction of stupid password rules on various websites.
Advantages:
- Open source. You don't have to use some random person's password manager software that you have no clue how or where the passwords are being stored or the trustability of the people who wrote the software.
- Portability. You can run this on any OS including a phone with a Python implementation, and it's pretty easy to port the above to any other language with a hash library.
- No files to lose. You don't need to worry about losing a password manager's database, you don't need to worry about syncing the database across machines, and you can compute the above on any machine that you own and trust. Kernel panics while you're on vacation? No worries! Reformat your PC with a fresh Ubuntu install and compute the above to get access to your bank account, plane tickets, and e-mail again.