At some point guessing the original input becomes tedious, when you’re trying to remember if your github password has name “github.com2” or “github.com-3”
Edit:
Completely forgot about another huge usability issue. Some sites enforce weird rules for what symbols are allowed, or what length your password should be. Every time your function generates something that doesn’t pass validation, you’re forced to pretty much revert to your pre-password-management behavior. Obviously you won’t remember that a year later when you suddenly realize that generated password doesn’t work.
* Are you sure your algorithm can't be reversed?
* What do you do if your normal username is taken?
* What do you do when the site's name changes?
* How do you handle forbidden and mandatory characters?
* How do you handle forced rotation?
* What about extraneous crap like security questions, phone PINs, emails, related sites, &c.?
* How do you access it on other devices?
* How can you track down old accounts to close them down?
If you go on listing the issues, you wind up writing the requirements document for a password manager.
One difference, though, is that most of the issues can be addressed by some sort of persistent data store that does not need high security. Once you've taken the passwords themselves out of what your password manager stores, I think this is the only thing on your list that requires storing highly sensitive data:
> What about extraneous crap like security questions, phone PINs, emails, related sites, &c.?
For the rest, such as some sort of per site version serial number to handle password rotation, or a map from current site name to original site name for sites whose names have changed, it is also sensitive data, but it is on a level of sensitivity like a contact list or browser bookmarks for which your ordinary OS security mechanisms for file protection should be sufficient.
Secondly, different sites have different requirements, so your generated passwords might not work everywhere.
Finally, a password manager lets you store more than just a password for each site, and it can let you store passwords and secrets for things other than websites.
Well I know Lesspass[0] has a 'counter' so that if you need to change a pass you simply increment it by one and you get a new hash
If your password gets leaked I can just: recognise that it's base64, decode it, see your salt and then all of your other passwords are essentially open to me?
Edit: Oh, is the salt different for each site? I don't get why you'd ever do this instead of generating an entirely new password though, you aren't solving the storage problem.
This doesn't solve all the other problems with this system, like what if there are multiple logins on the same domain? what if the site has esoteric password requirements? what if the requirements change? if your salt leaks you don't have a list of sites to know to go change your password. etc etc. Not my favorite solution for practical reasons, but it's cryptographically reasonable at least.