Better Password Security with Firefox

We all know how we should treat passwords. Use a mix of upper and lowercase letters, special chars and numbers. Choose longer passer passwords rather than short ones. Don't use the same password everywhere.

Well, you know that. I know that. But still, I was using two or three very insecure passwords on various websites again and again. Just because it's so much easier :-?. Until a few days ago.

Password Hasher Dialog That was when I discovered Password Hasher.

Password Hasher is a Firefox extension, helping you to make your passwords more secure.

The idea is simple: You continue to use your ridiculous simple password. But the extension creates a much more secure password from your silly password and the domain name of the login page. This secure password then is used to register and login at the page. This solves multiple problems:

  1. The password is harder to break because it's longer and more complicated
  2. You don't have to remember the complicated password
  3. The password is unique for this single website, if the site is compromised your logins for other sites are safe

Usage is simple. Just install it and whenever there is a password field to fill, open Password Hasher by one of the following methods:

  • Right click the password field and choose the Password Hasher menu entry
  • or Press Ctrl+;
  • or choose it from the Tools menu
  • or click the little # button right next to the field

In the dialog enter your (silly) master password and click OK. Password Hasher will fill the secure password into the field and you can login.

But what when you need to login and don't have your own Firefox? Just use the JavaScript online tool at the author's website to create the secure password.

Tags:
firefox,
passwords,
security,
extension
Similar posts:

 
Posted on Tuesday September the 11th, 2007 (8 months ago).

Comments

1
Just because the password looks more complex, does not mean it is more secure. The way I understand it, the password is a function of just two parameters: pass=hash(tag,master)

If someone knows your using this hash function (because you wrote it on your blog), and they can guess the tag of a site (which is easy), your master still needs to be strong for him not to be able to brute-force this. I would certainly not use the silly password.

Perhaps this does help though, to be able to use the same strong master for a whole bunch of sites. If one site is compromised, your master is not compromised, i.e. calculating the inverse of the hash function is not feasible.
2007-09-12 08:20:18
Bruno
2
Bruno you are right of course - for someone trying to attack exactly *my* password. So, one should still use an reasonable safe password.
2007-09-12 09:00:09
3
Hmmm, that`s an interesting extension. That may solve my password problem I wrote about a while ago.
2007-09-12 11:32:52
4
Great! I was looking for such an extension, especially with the possibility to save a portable version on my own server.
Once again I know why I love Firefox and why I like your blog so much. Thanks for this very useful hint!
2007-09-12 22:26:43
nlights
CAPTCHA

No HTML allowed. URLs will be linked with nofollow attribute. Whitespace is preserved.

 
 

Blog

Older Weblog articles are available in the Archive, subscribe to the
Full Content RSS Feed
to stay tuned. (learn more)

Subscribe to the Feed

Recent Blog Entries

 

This is the personal web site of Andreas Gohr - human being, blogger and web geek from Berlin, Germany.

This page was last updated at 2007/09/11 23:25.
Imprint/Impressum

Tagged at del.icio.us:
No tags, yet. Why don't you bookmark it?

View blog reactions

Elsewhere:


Recent readers: