Some non-secure login forms do still exist. Boardgamecore is one of them (shame away, the webmaster seems to think it's too expensive to get a cert and I can't talk sense into him). The whole internet knows my boardgamecore password.
I don't care too much though, because I use LastPass and that password is random. The worst you can do with it is make a bad move in my chess game. The fact that my board game password is public doesn't endanger any of my other security. My master password is still entirely out of reach.
But if I was using LessPass, you could use rapid offline cracking to derive my master password from my boardgamecore password. If you get lucky or if my master isn't strong enough, in short order you have my email and my bank and hundreds of other things, which I have to go change manually one by one after I figure out how to deal with the fact that all my money's gone.
With a deterministic password system, if somebody pwns you somewhere, they've pwnd you everywhere. It is only mildly better than reusing the same password everywhere. The danger of so many points of failure and no failsafety is definitely not worth the theoretical purity of "statelessness" (which you don't even really have because the state is in your head or a Google sheet)
Direct Debit also only works if you're an accredited recipient, because obviously under guarantee the bank is going to want to claw back that money it just refunded and so they need to know the recipient can afford that almost always. The huge global utility company won't go bankrupt if I unwind a monthly utility bill payment, but the fly-by-night vape shop might. Presumably ACH pull is the same?
Don’t use a trivial master password then… if you only need to remember one password, it may as well be one that can’t be cracked with a single fast hash, let alone PBKDF2x100000.
What? Has he never heard of LetsEncrypt or CloudFlare?
Changing master password is a pain in the ass which I did once since my original master wasn’t very strong but is doable. Plus, a master password should really be changed rarely IMO.
As for why stateless, it is much less work to get a new machine up and running. Plus, it is much friendlier at my current job since I can’t even send a word doc out to my personal email much less syncing a password vault. Much easier to have one stateless manager and separate spreadsheets for storing metadata.
you could also download your keepass file from something like dropbox either, but that would be a bit more effort if you were creating new passwords in work since you would have to upload it again after
No you don't. You can store it anywhere you like. It's publicly-safe information. The counter isn't a form of security; it's merely a vector to generate a new password from the master one. You could write the counter down on a piece of paper and show it to everyone and it wouldn't matter.
I'm still not sure that this system is a good idea, but I think "where do I store the non-password bits" isnt a big concern.
For a counterfield you can just use the domain name of the site for consistency.
But now you need to know how many times a particular site has forced you to change your password.
All of these things, including the counter, don't particularly need to be securely stored and can just be in a file in a git repo or Dropbox. Not needing to be securely stored eliminates many of the concerns with stateful password managers.
You're trusting crypto to not be broken either way, why not trust an encrypted file that provides significant usability rather than an unencrypted file and "stateless" generation algorithm?