TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Show HN: NilPass, the only password manager that's truly impenetrable

13 pointsby spbabout 8 years ago

3 comments

spbabout 8 years ago
While I first wrote an article about the absurdities of information security [in 2011][1], this specific extension is an idea I&#x27;ve had since [June 2015][2] - due to the absurd nature of the idea, I wanted to launch it on April Fools&#x27; Day, but that ended up causing it to be [dismissed as a joke out of hand altogether][3], so I figured I&#x27;d wait a day before posting it to Hacker News.<p>While the premise of the extension sounds like a joke, it&#x27;s legitimately a good idea, and [one others have had independent of this][4]. I explain some of the thoughts and motivations behind NilPass&#x27;s design here: <a href="https:&#x2F;&#x2F;nilpass.com&#x2F;seriously&#x2F;" rel="nofollow">https:&#x2F;&#x2F;nilpass.com&#x2F;seriously&#x2F;</a><p>[1]: <a href="http:&#x2F;&#x2F;www.cracked.com&#x2F;article_18962_5-things-we-all-do-that-make-hackers-lives-incredibly-easy.html" rel="nofollow">http:&#x2F;&#x2F;www.cracked.com&#x2F;article_18962_5-things-we-all-do-that...</a><p>[2]: <a href="https:&#x2F;&#x2F;github.com&#x2F;nilpass&#x2F;nilpass-branding&#x2F;commit&#x2F;6090b5cc972378832799d1c2a13ee8b12db88ca7" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;nilpass&#x2F;nilpass-branding&#x2F;commit&#x2F;6090b5cc9...</a><p>[3]: <a href="https:&#x2F;&#x2F;www.reddit.com&#x2F;r&#x2F;netsec&#x2F;comments&#x2F;62sgrp&#x2F;presenting_nilpass_the_only_password_manager&#x2F;dfova33&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.reddit.com&#x2F;r&#x2F;netsec&#x2F;comments&#x2F;62sgrp&#x2F;presenting_n...</a><p>[4]: <a href="https:&#x2F;&#x2F;rempel.world&#x2F;passwordless-method.html" rel="nofollow">https:&#x2F;&#x2F;rempel.world&#x2F;passwordless-method.html</a>
tscs37about 8 years ago
I see an incredible weakpoint: Your email account becomes your only defense, meaning the password on it must be strong and you still need to remember it. And you need 2FA.<p>Not that this is not the case already, email accounts are already important.
评论 #14021442 未加载
jszymborskiabout 8 years ago
Password managers are already a barrier. Forgotten Password flow via email is an embarrassingly shitty UX and similarly shitty security protocol.<p>I wouldn&#x27;t try to encourage the broken &quot;Forgotten Password&quot; protocol... it&#x27;s usually the softest target of authenticating on the web.