Hacker News new | past | comments | ask | show | jobs | submit login

Doesn't seem like a good fit for the paranoid. If you screw up and your master password leaks, an attacker can access all of your accounts.

I greatly prefer KeePass + Dropbox, which also lets you securely store usernames and notes. And the passwords are random and not derived from anything.




While it's not a perfect solution, most of the time you are not trying to protect yourself from a dedicated, thinking, hacker. Instead you're protecting yourself against automated systems that share passwords. Unless it was commonplace it would avoid a majority of those issues.


> Doesn't seem like a good fit for the paranoid.

Agreed. But OTOH it's a very lightweight solution, which is an advantage. And in any case, it's MUCH better than using the same unhashed password everywhere.

I'm claiming that using PwdHash is strictly better than not using it. YMMV.




Consider applying for YC's Spring batch! Applications are open till Feb 11.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: