https://github.com/lesspass/lesspass/blob/e134350f2b17b63a3a...:
salt = (
password_profile["site"]
+ password_profile["login"]
+ hex(password_profile["counter"])[2:]
)
It’s not ideal for “myusername” on “example.co”, “yusername” on “example.com”, and “yusernam” on “example.com” with counter 225 to produce the same password. Maybe it never affects anyone, but it’s so easily avoided there’s no reason to make this a hazard.`_insert_string_pseudo_randomly` seems overcomplicated compared to just putting `string` at the end, too.