Hacker News new | past | comments | ask | show | jobs | submit login

It's a bit of a cheat to argue this is stateless, given that the profiles (which stateful pieces of information which contain information about password complexity rules for each site, as well as which version of the password you're using) are synchronised with an online service. It is nice that you can self-host it though.

While I do applaud the idea (synchronising password databases manually is definitely something that gets on my nerves -- I use KeepassXC), I think the benefit of having completely random passwords that have no connection with each other is much higher. With systems like this, you have to have very strong confidence that your master password is very strong and will never be discovered. But with a file-based system, even if your master password is weak or compromised an attacker still needs to get an up-to-date version of your password file.

I'm also pretty sure I've seen this idea implemented a few times over the years (it's not clear to me if this is a new project or a reposting of an older project).




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: