|
|
|
|
|
by Lagged2Death
3248 days ago
|
|
...an attacker can use the knowledge of your password on site A to bruteforce your master password offline. This might be a concern if you're the victim of a state-level targeted attack. That's not a threat most of us have to deal with. Hackers aren't likely to spend a lot of effort cracking John Doe's password list; they want to steal a few million password hashes and sift out a few thousand easy or re-used ones. Your other points about the weaknesses of the scheme stand. Still, if we could get more users to use not-terrible, not-duplicated passwords, even with a flawed scheme like this, overall internet security would improve immeasurably. |
|
[0] https://www.theverge.com/2012/8/6/3224597/mat-honan-hacked-a...