Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

A serious deficiency in PasswordMaker is that, by default, it ignores subdomains, so bbc.co.uk and evil.co.uk would share the same password. But if you enable the subdomain option, then www.bbc.co.uk and www2.bbc.co.uk then have different passwords.


I'm using the Firefox add-on version 1.7.8, with the default URL Components settings (subdomains not enabled), and it uses "bbc.co.uk" as the domain for "www.bbc.co.uk" and "evil.co.uk" as the domain for "evil.co.uk", so the problem you described doesn't exist.

Maybe this was a problem in an earlier version and it's been fixed?


I'll have to double-check. The problem is still reproducible on the (albeit limited) PasswordMaker online version:

http://passwordmaker.org/passwordmaker.html




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: