Earlier quoted context omitted.
Ah, I hadn't considered that... That's a shame...
Just wanted to point out that any implementation as a browser extension (as opposed to bookmarklet) is safe from DOM manipulation; searching on Google for "supergenpass extension" returns results for at least Chrome, Firefox and Opera.
One way to fix your rubbish password database
91–94 of 94 posts
Re: One way to fix your rubbish password database
#92Earlier quoted context omitted.
Just wanted to point out that any implementation as a browser extension (as opposed to bookmarklet) is safe from DOM manipulation; searching on Google for "supergenpass extension" returns results for at least Chrome, Firefox and Opera.
I'm not so sure, the extension still appends DOM elements, I'm sure those are just as susceptible to sniffing...
Re: One way to fix your rubbish password database
#93Earlier quoted context omitted.
Red light coming up in the back of my head. Wouldn't the MD5->scrypt pipeline expose new attacks that scrypt doesn't have? Maybe there's a higher collision probability or some known-text attack, but I'm really shooting in the dark here.
No.
Re: One way to fix your rubbish password database
#94Earlier quoted context omitted.
Red light coming up in the back of my head. Wouldn't the MD5->scrypt pipeline expose new attacks that scrypt doesn't have? Maybe there's a higher collision probability or some known-text attack, but I'm really shooting in the dark here.
No.