pashword
AFFiNE
Our great sponsors
pashword | AFFiNE | |
---|---|---|
30 | 86 | |
265 | 30,494 | |
1.9% | 8.3% | |
0.0 | 10.0 | |
3 months ago | about 22 hours ago | |
TypeScript | TypeScript | |
GNU Affero General Public License v3.0 | GNU General Public License v3.0 or later |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
pashword
-
Show HN: Pashword – Hashed Password Calculator
This is beautifully done, great design work.
Scrypt for password stretching seems good. I see you're using CPU cost of 2^15. When storing a password hash you'd want to use 2^17 (with agility to change algorithm or increase cost in the future) [1]. Since you're not storing the result, I suspect the lower number is reasonable.
I don't like simple concatenation when building a salt from two variable length fields. You'll get the same salt for `"foo" + "bar"` and `"foob" + "ar"`, but the salt should be unique. Although I don't think that's an issue for this project since the first is a website.
Using the website in the salt has some issues when there are multiple domains that use the same password. Do I use mail.google.com, auth.google.com, or google.com? trello.com or atlassian.net? What if the website it bought and the new owner changes the domain name? With a password manager, I can just look in my vault to figure out the old domain name.
Phishing is a major way passwords are stolen and this project doesn't seem to do anything to protect against that. A browser extension (and mobile app), that checks the domain name before showing/filling the password could help.
The secret key field let me use `1234` as the key, although the color of the field was red. I think this should either prevent obviously weak passphrases or show a much more obvious warning if when one is used. Using a password found in a breach is also a bad idea (even it the password looks strong). You don't have a way to check HIBP, so users will be vulnerable if they make that mistake. It's too easy to make a critical mistake with the current design.
A bug: I filled out the form but forgot to enable JavaScript. The form posted my passphrase back to the server (https://pashword.app/?website=google.com&username=me&passphr...). I'd recommend changing the form so the submit button doesn't do anything when JS isn't loaded, otherwise the server will learn users passphrases. This is also a good place to remember that the user fully trusts that you wont steal their info (I'm not sure why anyone should trust that).
Also check out other similar projects, lots of discussion which likely applies here as well. I believe one of these supports uses a counter to support password rotation. You'd just need to remember the counter value for each site.
* LessPass - https://news.ycombinator.com/item?id=12889807
- Ask HN: Tools you have built for yourself?
- Hard reset every day
- Design-first open source softwares, is that a thing/possible?
-
Why Tailwindcss over styled-components?
Just take a look here: https://github.com/pashword/pashword/blob/main/pages/index.tsx
-
Good dark + gradients design systems?
I'm looking for something close to https://pashword.app
-
My epic account just got hacked, I just lost over 500 dollars worth of games and accounts.
Password managers can be a bit hard to manage, people don't even bother using them. There's https://pashword.app that solves this but not many people know about it.
- Pashword - A password generator that generates passwords you don't have to remember and cannot ever forget
- Pashword – A Hashed Password Generator
AFFiNE
-
Are we making the best notion open source alternative?
Also has a self-hosted version however it’s a bit out of date with their SaaS product
https://github.com/toeverything/AFFiNE#self-host
-
Quasi Self-Hosted Quasi Open Source Notion Alternatives from Asia (SiYuan, Affine, AppFlowy)
Affine.Pro - MPL Licensed - their unique selling point is the ability to switch between text and whiteboard view for the same page: https://github.com/toeverything/AFFiNE
-
Tell HN: Nearly all of Evernote’s remaining staff has been laid off
3. Affine: https://github.com/toeverything/AFFiNE
- Write, Draw, and Plan All at Once
-
Zotero Better Notes – Knowledge management solution insid}e Zotero
there's also this project that takes on that space, previously featured on HN but has made significant progress lately:
https://github.com/toeverything/AFFiNE
- Miro - MindMap Software Selfhosted Alternatives?
-
Anything you wish there was an open source solution for?
AFFiNE could end up there at some point. It's a web app so technically it should work on mobile, but I'm not sure how the user experience would be there.
- Is there a deep Notion alternative that includes both 1. thorough 'notion-database'-like functionality (Airtable or postgres or similarly backed) and 2. excellent integration/embed support for other apps and services?
-
which program should i use for this workflow?
any new idea or feature request welcome to submit to our Github and also welcome to contact me if you want~!
-
Hi Community, AFFiNE with new website and client is coming(support for whiteboard and collaboration!
After our last release to here, we have refactored all of our code, redesigned our new logo and new official website, and happy to announce that the client has also been ready to be downloaded and have a try.
What are some alternatives?
zxcvbn - Low-Budget Password Strength Estimation
AppFlowy - AppFlowy is an open-source alternative to Notion. You are in charge of your data and customizations. Built with Flutter and Rust.
gitgrep - Lightning fast code searching made easy
siyuan - A privacy-first, self-hosted, fully open source personal knowledge management software, written in typescript and golang.
hckrweb - Hcker News mobile web app
Outline - The fastest knowledge base for growing teams. Beautiful, realtime collaborative, feature packed, and markdown compatible.
rgca - Experiment in SSL CA management.
logseq - A local-first, non-linear, outliner notebook for organizing and sharing your personal knowledge base. Use it to organize your todo list, to write your journals, or to record your unique life.
pwgen-for-bios - Password generator for BIOS
focalboard - Focalboard is an open source, self-hosted alternative to Trello, Notion, and Asana.
Qwickly - An easy to learn keyboard layout that's fast and comfortable to type.
notea - 📒 Self hosted note taking app stored on S3