Use the same password on multiple sites safely
crypto.stanford.edu
crypto.stanford.edu
The real problem is that if you are security-conscious enough to understand how this works and why you need it, you are not using the same password over and over again. E.g. I have a "weak" password that I use on HN and many other sites, but my mail and sites that involve (even remotely) money get an individual password each.
Who do I send that suggestion to? :-)
I love PwdHash because it is a relatively simple solution to a relatively complicated problem. This is just further proof that "secure by design" is the only real way to do security.
There's an offline version as well.
I do use a weak password for throwaway sites, but I use hashing (supergenpass) to make sure the (weak) password is unique for each site.
It's also a particularly bad implementation that uses a single round of HMAC-MD5, which is a kind of bizarre primitive to use for hashing a password in the first place.
For that matter, this solution is probably even more complicated than it needs to be. Just tack on the domain name wholesale to the end of the password, and you'll foil any automated phishing password script well enough.
Of course you are, because this password does work on other sites. All other sites.
With a single high end CUDA capable graphics device you can blow through 500 million MD5 operations in one second. How many words are in an English dictionary? Less than that.
That's how weak this is. If you steal the password database from bigforum.com, you can attack all the passwords in parallel. If you crack a password, you can then log into their facebook, gmail, paypal, whatever. This scheme pretty much guarantees you can do that.
hash(password + domainName);
it did this? salts.put(domainName, randomString());
hash(password + salts.get(domainName));(Of course, copy and paste is not exactly convenient in mobile browsers, but it's at least possible on most newer ones.)