Show HN: Password.ly - Per site password generator from a master password
password.ly
password.ly
That it is not stored in a database is only a small advantage. If whoever controls password.ly wants to have all passwords, she could do so whenever she wants, a matter of a simple extra request. It could even be hidden in the params of any link on password.ly (to prevent you from noticing the extra request).
And that reveals the second big problem with this: The master password is basically every password. If it falls in the wrong hands you are worse off than you would be if you have a small set of passwords, which isn't a highly recommended strategy in itself.
But the idea itself isn't too bad, if you would instead of using password.ly use a terminal bcrypt command to bcrypt your password+sitename it would be very decent indeed.
The only way sites like this could be safe to use is if there would be a code-signing standard for the web.
edit: This service actually sends your password to their service! At first I thought it was an innocuous enough javascript password generator, but this is so stupid it borders on malice..
If you're worried about not trusting anyone, then you would need to set up your own solution - but for most people thats completely out of their league. This is intended for people who would be typing their master password in different websites, and now instead only need to type their master password into one.
I can't argue against the problem of only having one password, but the small set never worked for me. I have a couple plans to integrate password migration into password.ly.
How do I know the code released for review is actually the code they're running on their server? There is no way they can adequately prove this to me.
It has nothing to do with trusting anyone, if a service like this should grow out of obscurity it would naturally become a target for hackers, just like the Bitcoin exchanges did for example.
There is almost no protecting against this, the attack vectors are endless, and the bounty could be very large.
https://chrome.google.com/webstore/detail/password-generator...
Source: https://github.com/agiliq/forgot-me-password
Its not as good as this as we use use MD5 to hash the generated passwords - reason being this was proof of concept, and built mostly for our use. If anyone wants to add bcrypt - pull request is gladly accepted.
https://github.com/d-snp/scrypt.js
Note that some other guy wrote the javascript which was made for Node, I merely changed some types so it would work in the browser, I actually have no idea if it is still secure :P
Note btw, that as soon as tptacek wakes up he'll wack everyone around with his staff until we understand that we are fools for messing about with javascript security.
And he should, because he would be right for it. This whole article should be banned, and I have flagged it, because it is a terrible idea and no one should be fooled into using this service.
But I agree, this should be a browser extension, not a website.
Edit: btw, found this: http://www.lorrin.org/blog/2011/06/15/a-fruitless-search-for...
Looks like there are a few bcrypt js library - why would using them be too heavy?
def generatePassword(password, site):
letters = 'abcdefghijklmnopqrstuvwxyz'
u_letters = letters.upper()
all_letters = letters + u_letters
numbers = '0123456789'
symbols = '!@#$%*-?+='
length = 10
i.e. a 10 character password is generated from an alphabet with 72 characters in it. That gives 10 * log_2 72 which is roughly 61.7 bits.Currently you'd want to have at least 80 bits for a good password.
Of course, it's trivial for them to fix this given that they are generating the passwords: just change length to 13 or greater.
Unfortunately while changing the 10 to 13 was a rather trivial change yesterday, now that the site has launched its not really possible. It would change and break everyones password on the site.
That said the entire thing is open-source, so anyone 'could' set up a version of password.ly with length=13 for themselves if they wanted.
Your system is creating the passwords server side and so taking the user's "master" password in. Where as SuperGenPass is purely javascript based and runs completely in the browser; thus is safer.
Also being a bookmarklet make's it more convient, as you can just click the button from within your browser toolbar, rather than having to go to a sepearte site, remember exactly what you put in the "Create password for:" input, did you put the domain with a www or without? with http:// or https:// ?
<input type="hidden" name="hash" value="$2a$11$1aRIk1567CsvOEGMEKlalOteGiqsy9APgBfI/5ZtPJvQgQkvxC1.G">
Use the '$2y$' form to ensure you're using the fixed version, at least, though I recommend something more along the lines of scrypt to be more robust against attack. And do you really need to pass the value in plaintext in the returned form? Just pass the hash value of the master password and put some fake stars in the form field to reduce the possibility of an attacker gaining the plaintext version of the master password from the browser.All of this of course ignoring the problem of just generating lists of passwords based on commonly-used master passwords and service names, but i'm sure you all realize that problem.
There is no database to lose, or not have access to if you're on another machine. It also has a command line client which works completely offline (though has sync if you're signed up and want to save sites/comments)
This may be obvious to users here, but to most people the fact that the generated passwords seem random may lead to a false sense of security in this matter.
My initial impression was "no thanks" because 1Password will type my passwords in for me, a huge benefit. But maybe password.ly can or soon will do this?
In other words, IMO the landing page doesn't have enough info.
EDIT: ahh, now I see the link to the command one tool at the bottom.
It's really just a MVP at the moment. There are quite a few improvements planned, and definitely a browser extension if there is any interest.
At the moment it is limited to the password generator, site names along with comments saved when you've signed up and a simple command line tool.
Though I recently had to wipe my android phone and getting those long passwords in to every app was NOT fun.
I think I already know the answer (it does), but maybe someone can correct me if I'm wrong.
There is a 'pw sync' command which does send your password to the server (in order to confirm your access while updating saved comments/etc) but that is all.
First, I generated an 8 character password using pwgen (great program, btw) that is just mixed-case. I then add several characters based on the name of the website/service I'm logging into.
Using this, I can easily remember my password to everything, and each one is unique.