Hacker News new | ask | show | jobs
by gry 3007 days ago
You can use a YubiKey for a portion of a master password. This is best used by manually typing "correct" and autocompleting the latter portion with plenty of entryop of the password/phrase "battery horse staple" from the key. This way, if someone steals the key, you've still got a secret.

You'll still need a password manager to store the unique passwords for your services.

https://www.yubico.com/support/knowledge-base/categories/art...

https://www.yubico.com/wp-content/uploads/2015/11/Yubico_Whi...

EDIT: Explanation

1 comments

I think that advanced malware can intercept this master password and decrypt all data. I had in thought some hardware, which stores all passwords, reveals only metadata and to actually retrieve a single password, you have to physically interact with device (tap it, for example). In this case even if malware has full control over your PC, it can't retrieve all passwords, only those you've actually used.