Live data from Hacker News

Show HN: Forgiva – Never saves your passwords but regenerates them

forgiva.com

11–20 of 98 posts

Re: Show HN: Forgiva – Never saves your passwords but regenerates them

#12
As an end user, I don't care about how the passwords are stored. I care mostly about two things:

1. How hard it is for someone to steal them 2. How easy they are to retrieve when I need them

I'm currently really happy with 1Password on both counts, and I don't really understand why I should move. A competitor would need to establish that they are at least as secure as 1Password, and this landing page doesn't do that at all. For all I know, it's been built by a nefarious hacker or some junior Node.js developer who's just discovered security.

Has it been audited? What is the roadmap for the project? These things are much more important than some technical explanation that I didn't really understand.

Re: Show HN: Forgiva – Never saves your passwords but regenerates them

#13
post #10

I use getvau.lt, how does this compare?

Same strategy but Forgiva doesn't just use one key derivation algorithm (such as PBKDF2) but plus various hashing and encryption algorithms too.

And at the same time you may forget the options you used in Vault, it is not an option in Forgiva.

Re: Show HN: Forgiva – Never saves your passwords but regenerates them

#14
Your password will never be secure when you store it on someone else his disk or let someone else encrypt your password. Its not a matter of how, but when there will be a way to retreive those passwords by anything but you.

And its not just that, everything you use your passwords for these days, is stored on some sort of storage in a cloudy architecture. Scattered all over the world in thousands of datacenters. You probably are currently trusting thousands of people working over there, but you dont even know these guys. Terrible imho..

Re: Show HN: Forgiva – Never saves your passwords but regenerates them

#16
post #8
post #3

How does this compare to the KeePass family of pw-managers? (Besides that Forgiva is closed source and KeePass is open source.) Fixes poor passwords, accessibility and storage problems with highly secure way. What does that even mean?

The way I read it... it's a password manager that doesn't store passwords (centrally or locally). Instead it regenerates the password each time. i.e. password for HN may be: some trait of HN (domain?) + some salt + your identity (cert?) to always produce the same password. I didn't understand it all from the site, the explanations and broken English didn't really elucidate. But... if my understanding was right, I won…

Seems like a really cool idea, as long as the password generator can be proved to be hard enough to break.

How long does the retrieval of a password take? Sub-second? 10 seconds?

Re: Show HN: Forgiva – Never saves your passwords but regenerates them

#17
post #3

How does this compare to the KeePass family of pw-managers? (Besides that Forgiva is closed source and KeePass is open source.) Fixes poor passwords, accessibility and storage problems with highly secure way. What does that even mean?

It looks like it isn't completely closed source, https://github.com/sceptive/Forgiva.

Re: Show HN: Forgiva – Never saves your passwords but regenerates them

#18
What would happen if the site's domain changes? Or my email changes? Or something else about the metadata changes?

Now what if this happens on a site where you can not reset passwords, such as blockchain.info, am I SOL?

I like storing passwords becuase I have 100% certainty that it won't just magically generate the wrong one.

Re: Show HN: Forgiva – Never saves your passwords but regenerates them

#20
post #12

As an end user, I don't care about how the passwords are stored. I care mostly about two things: 1. How hard it is for someone to steal them 2. How easy they are to retrieve when I need them I'm currently really happy with 1Password on both counts, and I don't really understand why I should move. A competitor would need to establish that they are at least as secure as 1Password, and this landing page doesn't do that…

from the About page:

"Well respected, international company based on Istanbul which works only with underground talents.Hacks big corporations for good and creates trusted relationships and work hard to protect them against Sith Lords. Helps companies to strengthen their security layers and provides educational services."

Post reply on HN