You can find this tool online and as a chrome extension
THIS IS NOT NEEDED, see link above.
How to install this unpacked chrome extension:
chrome-extension (link to zipchrome://extensionsThe chrome-extension should now be present
The hash generated gives you up to 160bit password strength, depending on the passphrase. Passwords are unique for every website, since the domain is used in the hash.
You could have multiple passphrases, e.g. one for all work related, one for social media etc.
NOTE: some websites have a max length on a password, resulting in lower possible strenght. Services demanding a short password could indicate bad security.
Found out later that lesspass does the similar thing.
but requires more parameters and does not come preinstalled (shasum).
It is inspired by Stanford PwdHash
and works by doing
base64( shasum(apex.tld + PASSPHRASE) )
It is a concatenation of the domain you want a password for, together with a phrase that you use. This string is then used to calculate a hash. This hash uses base16 or hexadecimal resulting in 40 characters, which we convert to bas64 (28 characters).
Since multiple websites have a upperlimit of 32 characters for a password, this tool now only supports 28 character (160bit) passwords.
We do two SHA rounds, preventing brute force searching for the master passphrase (not needed atm. but makes it future proof).
The first round (sha512sum) to prevent an offline attack when 1 or more passwords are leaked
and the second round (sha1sum) to have 40 characters base16, which we convert to base64, resulting in 28 characters.
echo -n 'apex.tldPASSPHRASE' \
| sha512sum \
| tr -d '\n -' \
| sha1sum \
| cut -f1 -d' ' \
| xxd -r -p \
| base64
# or all on one line
echo -n 'apex.tldPASSPHRASE'|sha512sum|tr -d '\n -'|sha1sum|cut -f1 -d' '|xxd -r -p|base64
(to avoid storing history, prepend a space to echo)
This provides us with 28 chars of which the last one is a special char ('=').
We tested this with 1M records
for i in {1..1000000};do echo -n $i|shasum|xxd -r -p|base64;done
and found out that 9858 have no number [0-9], 0 have no letter [a-z] and 2 have no capital letter [A-Z]. To be sure that all three type of characters are present, we append
|grep [0-9]|grep [A-Z]|grep [a-z]
to our initial command. If we now get no output (probability of 1%), we know one of the character types was missing. We solve this by prepending a 'p' (referring to padding) to our initial input, giving us 'apex.tldPASSPHRASEp'.
But don't worry, the tool does this for you, it's just to explain the inner working of this tool.
Some services have a password limit, ranging from acceptable (e.g. 32 at digid.nl or namesilo.com) to short (e.g. 20 at paypal.com and 16 at microsoftonline.com).
When 28 chars. is too long, we reduce it to 12, which should always fit. The same padding technique applies here, making it occur more often for shorter passwords.
To achieve this on your terminal, just append
|cut -c17-28
to the command.
The motivation for this password manager was the backup requirement of normal password managers, which need to be done secure. One colleague of mine once had his password manager report that the file was corrupted, resulting in the lost of all his passwords, thus the backup should also have versioning.
This solution does not have this requirement, you just remember the master passphrase(s).
Disadvantages compared to password manager;
Other disadvantages;
shasum was chosen,
since it comes pre-installed on most machinesGenerated a password in the past? The old version can be found here
Content type
Image
Digest
sha256:3c291b9b6…
Size
447.7 kB
Last updated
about 4 years ago
docker pull svlentink/pwdgen-data