Gentoo Archives: gentoo-user

From: Tanstaafl <tanstaafl@×××××××××××.org>
To: gentoo-user@l.g.o
Subject: Re: [gentoo-user] Questions about hacked sites and passwords
Date: Tue, 17 Jan 2012 13:01:11
Message-Id: 4F1570D7.4090002@libertytrek.org
In Reply to: Re: [gentoo-user] Questions about hacked sites and passwords by Neil Bothwick
1 On 2012-01-17 7:50 AM, Neil Bothwick <neil@××××××××××.uk> wrote:
2 > On Tue, 17 Jan 2012 07:37:38 -0500, Tanstaafl wrote:
3 >
4 >>> I'll stick with KeePassX, the password database is
5 >>> stored and encrypted locally. Even if I put it on DropBox, hacking
6 >>> that will only give the encrypted database.
7
8 >> And I'll stick with passwordmaker, which doesn't store the passwords at
9 >> all, anywhere...only the account settings used to generate them, which
10 >> are useless without the Master Password...
11
12 > It comes to the same thing really. whether you store the passwords
13 > themselves or the methods and data used to generate them, both systems
14 > are as strong as the master password and useless if that is compromised.
15 > So stick with whatever suits your way of working. Choice is good :)
16
17 This is actually not correct...
18
19 Since PWM doesn't store the passwords, there is nothing to 'crack'...
20 there would never be any way for an attacker who got ahold of your RDF
21 file to run an attack program against it - how would the attack program
22 ever be able to determine 'success'?

Replies

Subject Author
Re: [gentoo-user] Questions about hacked sites and passwords "Érico Porto" <ericoporto2008@×××××.com>
Re: [gentoo-user] Questions about hacked sites and passwords Neil Bothwick <neil@××××××××××.uk>