To answer your question, AFAIK there are no known first preimage attacks on SHA-1 yet.
And no, your method is not secure.
And no, your method is not secure.
1. The pass is long
2. The preimage is known
If nobody can find `sha1(knownpart|hiddenpart)`, how is my method insecure?Is the problem linked to sha1 or if I use any other hash this method also fail?
I presume the _only_ method you advocate for is to have a lot of different passwords for each website is to store randomly generated password inside a keychain system. Could you enlighten me? How do you deal with your own password?
Thanks.
edit: it seems we reached the max depth. Thank you Dmitry!
I personally use a scheme similar to yours, but with PBKDF2. Also, I'm no crypto expert.