KBD

Keith Devens .com

Saturday, August 30, 2008 Flag waving
I meant what I said, and I said what I meant. An elephant's faithful, one hundred percent! – Horton (Horton Hears a Who, Dr. Seuss)
← alexking.org: Software > JavaScript Functionsvideo - blindfolded mario pianist take two →

Daily link icon Monday, September 6, 2004

Password generator bookmarklet

Simon Willison: The bookmarklet solution to the password problem:

Nic's bookmarklet pops up a JavaScript prompt box asking for your "master" password, then MD5s it against the domain of the current login page and inserts the resulting hash in to any password fields on the page. A single password can be used for dozens of sites without any risk of a compromise of one account affecting the others. It's brilliant.

Here's the bookmarklet. Even if the login URL does change you can just have your password either reset or sent to you by the site and then set the new password using this script. Unfortunately, some login pages change all the time. I'm pretty sure Amazon's works this way.

← alexking.org: Software > JavaScript Functionsvideo - blindfolded mario pianist take two →

Comments XML gif

Nic Wolff (http://angel.net/~nic) wrote:

Hi - thanks for your interest in the passwdlet. Just to clarify, it uses only the hostname from the current URL to hash with your master password, not the whole URL - it'll work fine at Amazon.

∴ Nic Wolff | 16-Sep-2004 9:34pm est | http://angel.net/~nic | #5601

Keith (http://keithdevens.com/) wrote:

Ooh, sexy. Thanks Nic!

Keith | 16-Sep-2004 9:37pm est | http://keithdevens.com/ | #5602

dilvie (http://www.dilvie.com/) wrote:

That's a really cool concept. There are a few obvious problems with it, though:

- A lot of the most important passwords (ie, online banking) have very specific password rules that an MD5 sum will not work for.

- Often, there will be one password that spans multiple domains (ie, a network of related websites all sharing the same login database).

I threw together a password tool that can generate passwords that would work for those conditions. It generates word-like passwords that are (sometimes) easy to remember or type.

∴ dilvie | 9-Dec-2004 6:22pm est | http://www.dilvie.com/ | #6560

Chris (http://chris.zarate.org/) wrote:

Here's a version of Nic's script that will ignore subdomains--very useful for those sites that have multiple login points.

http://labs.zarate.org/passwd/

∴ Chris | 4-May-2005 2:21pm est | http://chris.zarate.org/ | #7588

Keith Gaughan (http://talideon.com/) wrote:

So what about a domain like bbc.co.uk, or yahoo.com.au?

∴ Keith Gaughan | 5-May-2005 12:09pm est | http://talideon.com/ | #7594

Chris (http://chris.zarate.org/) wrote:

Keith, it briefly didn't support those URLs, but now does, and has for a few days.

∴ Chris | 9-May-2005 12:22pm est | http://chris.zarate.org/ | #7620

Feel free to post a comment below. Please see my comment policy.

Formatting Rules (No HTML):

  • **bold**, *italic*, _underlined_, --strikeout--
  • "text"="url" creates a link, and URLs are auto-highlighted
  • Blockquote: Like e-mail, begin paragraph with > (greater-than sign)
  • Lists: begin paragraph with *,-, or + (unordered), or # (ordered)
  • Code block: ?!code:language=perl|php|sql|javascript|etc.{\n}...{\n}?!/code

:
(will be your IP address if blank)
: (optional)
(Will not be shown on site)

: (optional)
:

August 2008
SunMonTueWedThuFriSat
 12
3456789
10111213141516
17181920212223
24252627282930
31 



RSS feed RSS feed for Keith's Weblog
Atom feed Atom feed for Keith's Weblog
Weblog archive
Recent comments
  on 2 posts

Recent comments XML

new⇒Johnny Walker Blue Label

Wow, thanks for the scotch review​:D

Lagavulin and Laphroaig are​some of...

Keith: Aug 29, 3:35pm

Girls, please don't get breast implants

Wow, After all this time, the​comments on this page continue to​grow. It wa...

Ajeet: Aug 25, 2:36am

Generated in about 0.133s.

(Used 8 db queries)

mobile phone