Sure, it's kind of a pain (I can only sync on my home network) but worth the trade off to me. I mean how often do you have to sync passwords?
If my account is compromised, the attacker has one DB for their effort. If a cloud storage is compromised, the attacker has to scan through everything looking for DB files.
LastPass cloud storage is meant only for storing password DBs, so an attacker knows that within a single target lies a large trove a specific type of data.
I'm skeptical that a) our hypothetical attacker couldn't search for files to get all of those synced 1Password files or b) that such a complete compromise wouldn't turn over enough interesting personal docs to make the potential resale value quite lucrative – “They got my tax return but fortunately not my nytimes.com password!”. In either case, pure worst-case analysis isn't terribly useful without some concept of relative likelihood.
With 1Password and Dropbox the 1Password master password and the Dropbox login password should be unrelated. My Dropbox password, in fact, is a long password generated by 1Password's password generator. If someone gets a hold of it by compromising Dropbox, they might then get a copy of my encrypted passwords, but they get no clue to my 1Password master password.
There is some unencrypted non-password data in 1Password's data, so I'd not be happy if Dropbox were compromised, but it would not be a disaster.
http://angel.net/~nic/passwdlet.html
Storage is unnecessary. LastPass, 1Password... every one of them has centralized storage. No one needs a central server, but a central server is the only way a "service" can sell itself.
You linked to the old version btw. Updated version is here: http://angel.net/~nic/passwdlet.domain.html
As you note, SHA isn't appropriate for this purpose. PBKDF2-strenghtened SHA, SCrypt, BCrypt and other functions should be used.
Or, and more to the point, having generated a different password how do you remember which sites need a V1 password and which need V2?
When sites introduce silly rules around password structure, how do you make sure your passwords conform?
And even if you could guarantee you'll never hit any of these issues, shouldn't you be using a key-derivation function, rather than a hash?
I entrust my passwords to KeePass, as I trust its authors to have more of a clue than me and it lets me store arbitrary data rather than restricting me to a specific class of generated password. That file can then be replicated to enough of my devices that it's available when I need it, without a third-party having enough access to the data to be able to issue even the kind of security alert we see here.
> When sites introduce silly rules around password structure, how do you make sure your passwords conform?
Store _THESE_ rules in a central database. Not the passwords. Those rules can be public at no cost to security to the end user.
But LastPass, KeePass, OnePass and all sorts of Password generators store the actual friggen password, instead of salts or public information (like "5th password on gmail")
1. Some sites use email, others use username (and sometimes your usual username is taken), and a handful of sites assign you something (eg: with an old VoIP provider I used to use, I had to log in with my customer number instead of a username)
2. I use a unique email address on every site, in the form "domain-i-am-logging-into.com@something.mydomain.com", though occasionally I have "companyname@something.mydomain.com" (eg: I use "amazon@" because I my account works with both amazon.ca and amazon.com)
LastPass remembers all this crap for me, and it also lets me keep other notes, password history, etc, as well as being quite convenient.
Use lowercase hexadecimal as the "baseline" password. From there, truncate to the length requirement, and add symbols to the end to guarantee complexity requirement.
For example, "masterpass gmail.com" will md5sum to "194b52e5". If a password requires symbols, add a "!" to the end. If it requires a capitol letter, add "A" to the end. Add in the order of "number->letter->symbol". So... a site that requires numbers, capitol letters, and symbols would be:
"194b52e51A!". (The hashed password, followed by '1A!')