Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

For if you really want a "secure" password sent over HTTP, I presume...


Sent over HTTP and generated on a remote machine, which could theoretically log it along with your IP. </paranoid>

Alternate ways of generating strong passwords on your local box that I'm aware of:

* Mac OS X users can launch Keychain Access, click the + button, then the Key button on the very right. This gives you a dialog window which will generate strong passwords in various configurations, such as memorable ones.

* The pwgen utility is available on several Linux distributions and on Macports. It too can generate memorable passwords. Check out the -s and -y command line options and note that you can give the desired password length on the command line.

Any other recommendations?


* apg http://www.adel.nursat.kz/apg/download.shtml generates per default pronounceable/memorable passwords. From the debian package description:

APG (Automated Password Generator) is the tool set for random password generation. It generates some random words of required type and prints them to standard output. Advantages:

  * Built-in ANSI X9.17 RNG (Random Number Generator)(CAST/SHA1)
  * Built-in password quality checking system (now it has support for Bloom
    filter for faster access)
  * Two Password Generation Algorithms:
     1. Pronounceable Password Generation Algorithm (according to NIST
        FIPS 181)
     2. Random Character Password Generation Algorithm with 35
        configurable modes of operation
  * Configurable password length parameters
  * Configurable amount of generated passwords
  * Ability to initialize RNG with user string
  * Support for /dev/random
  * Ability to crypt() generated passwords and print them as additional output.
  * Special parameters to use APG in script


At least they are embedded in images.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: