Re: Online password manager



I read through the Host-proof pattern, and I may be missing something,
but I just don't believe it.

If you don't trust them to hold your passwords, how can you trust them
to provide the JavaScript that protects them? They don't need a
script that walks the DOM tree to find your key since they wrote the
DOM to begin with. One or two lines of code is all that is necessary
to send the key back. That isn't even going into the more evil ways
of sending the password back. What if they choose to send back an MD5
hash of your key (so they know which key is associated with with
password)? All they need is a good rainbow table on their end to
recover many of the keys.

As I said, I may just be missing something, but this whole pattern
seems badly broken unless it is only intended for use by:
1) Browsing to the page.
2) Unplugging your computer from the network
3) Entering your key and getting the passwords you need.
4) Closing your browser and clearing all cookies for that site.
5) Reconnecting to the network.

I realize that they mention this risk, but as this fundamentally
undercuts the entire goal of the pattern, it seems rather severe.

Give me password safe on a thumb-drive any day.

Greg



Relevant Pages

  • Re: intelligence
    ... Morse code program gave me any insight I didn't already ... pattern problems better than the way it is already done. ... network correctly solves, and which it is yet to solve, you don't seem to ... The pulse sorting network you know about creates a hierarchy of pulse ...
    (comp.ai.philosophy)
  • Re: New kid on the block
    ... network, and the other, is why did the visual cortex distribute ... pattern learning machine. ... IT's a high quality GENERIC sensory pattern ... The only way to explain how the brain has the generic learning powers it ...
    (comp.ai.philosophy)
  • Re: Can operant conditioning account for all learning?
    ... How the brain deals with asynchronous data is a question ... You liked to talk about pulses of infinite small widths ... network that are too close together they blend into one ... pattern and s,t and u are examples of the cat pattern. ...
    (comp.ai.philosophy)
  • Re: Can operant conditioning account for all learning?
    ... pattern and s,t and u are examples of the cat pattern. ... "temporal" gates wired up in what topology. ... The pulse routing network should scale correctly as long as it doesn't have ...
    (comp.ai.philosophy)
  • Re: Does Searles "Chinese Room" argument imply that consciousness is non-scientific?
    ... only when nodes in this network detect a pattern, ... "the PART of the brain which produces conscious ... that's consistent with the network of detectors model. ...
    (comp.ai.philosophy)