Hmmm. Such a statement should be backed by proof, not by trust. Until you can run the code locally you can't assume that any of these things is true. As far as we know, this can be a reverse password harvesting scheme.
Hmmm. Such a statement should be backed by proof, not by trust. Until you can run the code locally you can't assume that any of these things is true. As far as we know, this can be a reverse password harvesting scheme.
Just noting that "Cheswick" is the dude that literally (co-)wrote the book on firewalls (1e in 1994):
* https://en.wikipedia.org/wiki/Firewalls_and_Internet_Securit...
But now that you mention him, the man was working at Bell labs during the time when Ken wrote his famous essay "reflections on trusting trust". If he shared just a small part of his colleague's spirit, it would be irresistible to him to log all passwords that thousands of people may decide to use. Mainly as a conversation starter, not to do anything bad with these passwords. Maybe he's gathering cool stories in case of a hypothetical Turing award in the future?
GP was arguing that OP is trustworthy because he has a reputation to maintain.
I, the GP, is arguing nothing of the sort.
That being said, there's no need to use 3rd party password generators, if you can make your own.
Really?
1. It’s from a known-reliable source
2. Even if the password is stored, logged, broadcast around the world for billions to see, so what?
A. Source has no way to know if the user used the password anywhere or saved it
B. Source doesn’t know who the user is
C. Source doesn’t know in which website or resource the password was used.
So… I stand by my paranoia claim. I wouldn’t go so far as to call you foolish like you did me, but I’d say such a world view will not be a net gain for you over your lifetime. You’ll have difficulty delegating work. You’ll have major trust issues. Maybe you already do. But as they say, “you do you.”
But being able to inspect (theoretically even audit) the source, building (if necessary) and running it locally in some container/sandbox without network connection would be minimum reqirements for me.
Open source, runs on your machine.
It makes passwords like:
tiptoeing saxophone wholesaler luxurious leftover codeword eruption gnarly skies taco username affidavit
I named it pgenGet it from https://github.com/ctsrc/Pgen
shuf -n 5 /usr/share/dict/words
and then manually typing them in, optionally adding any special characters or whatever the particular site requires. Changing 5 as needed, of course.If so, please let me know the name of your SaaS so I can steer well clear of it…
https://git.sr.ht/~jamesponddotco/acopw-cli
It can generate diceware passwords, random passwords, PINs, and UUIDv4.
It uses my own Go module for this, which comes with a list of words with over 23 thousand words:
Hit ctrl+s
Which you should do even if you fully trust the website owner anyway
Great username btw
If we are using a password manager as we should be, there is no real justification for using memorable passwords for the majority of passwords. Let’s use the example from XKCD:
correct horse battery staple = 2048^4 = 2^44
If instead we use the same length of 28 characters with the full range of characters allowed by most websites:
M4Uk@gQRU!JFgwlI6MV$VV39TEA. = 70^28 = ~2^172
Dunno about you, but I’ll gladly take significantly more entropy with zero extra cost any day.
>> using a password manager for
>> the /vast majority/ of passwords
Added emphasis to what I said previously to show I had answered that already.
But If I need to login on a device where my password manager is not installed, or you can't use a password manager (e.g. windows UAC prompt, linux tty), it will be way easier to open my password manager on my phone and type a password rather than a long random string.
I don't use a passphrase for every login, but for some logins where I think it could be benefitial to easily type it without using autofill I use them.
See my reply to sibling commenter, I had already covered this case in my original post.
>I don't always drink beer, but when I do...
Secondly, jsjohnst was not supporting silly password rules, merely pointing out that a password manager can make the password rules less of a hassle to comply with [https://news.ycombinator.com/item?id=39690528]:
> Also, many sites have arcane password complexity requirements (protip site owners, the only thing that really matters is length)
IMO, pass phrases only seem useful if you have a quite insecure password. It is ideal to aim for 115-128 bits of entropy, which is not that bad with just random lower case letters and numbers (24 characters is good) but turns into a long and complex passphrase. To learn a random password write it down (split into groups of 6ish characters) and copy it from the paper for 2-4 weeks (do not try to guess until you are almost certain your guess is correct).
Security is no issue if you don't care. They did abolish unhashed storage after a while (and a while is really quite recent).
[1] - though now that I think about it, that might not properly cover the case of leading zeroes in the password, so the total number of possible passwords might be larger than 10B; that's assuming a naïve password list generated just from numbers, not from treating the digits as characters, so I need to reason about this a bit more...
[1]: https://cheswick.com/ches/cv/index.html
EDIT: Pardon my sudden lack of linguistic finesse, clearly the beer I had tonight was good.
However, anyone taking this thing as anything more than the jovial manner in which it is intended is not someone that understands a word of what you just said. So it's all just grandstanding for the sake of it