Neat, but SuperGenPass does this better- has a bookmarklet with configurable salt, and it's based off the domain name, not the service, so you can't get into ambiguities (Gmail, GMail, gmail?)
"The SuperGenPass UI is rendered within the DOM of the current page when you click the bookmarklet. The UI is where you enter your master password. And because the UI is part of the current page, any script running in the page can read your master password. Remember that script can be external too, as in advertisements or widgets of some kind." -
http://akibjorklund.com/2009/supergenpass-is-not-that-secure
Comments
Neat, but SuperGenPass does this better- has a bookmarklet with configurable salt, and it's based off the domain name, not the service, so you can't get into ambiguities (Gmail, GMail, gmail?)
http://supergenpass.com/
That said, the options for disallowed characters is nice.
"The SuperGenPass UI is rendered within the DOM of the current page when you click the bookmarklet. The UI is where you enter your master password. And because the UI is part of the current page, any script running in the page can read your master password. Remember that script can be external too, as in advertisements or widgets of some kind." - http://akibjorklund.com/2009/supergenpass-is-not-that-secure
There are even a couple of demos:
http://akibjorklund.com/files/2009/10/supergenpass-vulnerabi...
http://akibjorklund.com/files/2009/10/supergenpass-vulnerabi...
I tested both demos with the latest version of SuperGenPass (2.01) from http://supergenpass.com/