Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> Seems like way too much work for an attacker to try to figure out.

I dunno, seems like way more work to come up with, maintain, and actually use the generator. Seems easier to just click a bunch in my vault to generate and copy, although I guess you're protected from vault-theft?

Given your example, I had already figured out all the way up to ies/otto are probably foreign numbers (more specifically, otto looks like 8 and 16 looks like double of 8) before even seeing that you just gave the answer away.



Give me some time with him and a $5 wrench an I can "steal" his "password vault" - https://xkcd.com/538/




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: