https://www.usenix.org/sites/default/files/conference/protec...
Whereas the README uses URLs as the realm string, the slides uses realm strings like "root-password" or "ssh-v2" to derive keys from a seed stored in a UEFI variable.
I think the idea is that you can administer all of your servers with one master password, while each server derives different passwords locally from its own seed. If a given seed is compromised, rederive the passwords from a new seed (or reprovision the server from scratch). If your master password is compromised ... well, try not to let that happen.
Good thing that keyloggers don't exist then... :'(
It just takes one compromised password to start a dictionary based or other offline attack to brute force the master password which would then allow the attacker to regenerate other realms.
Disagree. I'd even call required rotation a smell.
Requiring rotation leads to people coming up with passwords more frequently, meaning they'll likely choose weaker passwords. On top of that, regular rotation isn't necessary for passwords generated independently by a password manager.
The issue here is that there's no way to deal with revocation / password changes if a service is compromised.
https://github.com/cloudflare/gokey/blob/v0.1.0/csprng.go#L2...
.....because if so, let me introduce you to the Toyota Mega Cruiser: https://en.wikipedia.org/wiki/Toyota_Mega_Cruiser