TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Spectre: Goodbye Password Managers

4 pointsby michidkover 1 year ago

4 comments

MissTakeover 1 year ago
Am I missing something?<p>It would seem to me that knowing the specter secret key and the “login id” then exposes the password that then is “fixed” and cannot be changed without breaking other aspects.<p>In a world where we’re moving to passkeys and hardware based authentication, why is this even a thing? It just seems a huge step backwards.
spansoaover 1 year ago
Deterministic password managers have their caveats:<p><a href="https:&#x2F;&#x2F;tonyarcieri.com&#x2F;4-fatal-flaws-in-deterministic-password-managers" rel="nofollow noreferrer">https:&#x2F;&#x2F;tonyarcieri.com&#x2F;4-fatal-flaws-in-deterministic-passw...</a>
al2o3crover 1 year ago
How is this not &quot;use the same password on every site&quot; but with extra steps?<p>Seems like the &quot;Spectre secret&quot; is a massive risk given that compromising it once without detection would compromise EVERY PASSSWORD THAT USER USES, even ones that didn&#x27;t exist when the secret was stolen.<p>Followup question: how does Spectre plan to prevent malicious SEO-squatting like we already see in the cryptocurrency space? If this was used widely, I&#x27;d assume that the search results for &quot;compute Spectre password&quot; would be 100% stuffed with sites that capture the secret...
评论 #37419948 未加载
jpeizerover 1 year ago
If you are the owner of the site may I make a single recommendation. In the domain field set the casing to all lowercase. Depending on the device fields like that want to start with a capital letter, thus changing the output password.