frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Ask HN: Feedback on my stateless password manager (no stored secrets)

1•yoyo250•5h ago
Hi HN,

I built a prototype password tool that never stores passwords or vaults. Instead, it derives them on the fly using:

* A hardware OpenPGP key (smartcard/YubiKey/etc.)

* User inputs (domain + login + a simple passphrase)

* Deterministic signing + KDF

So as long as you have the hardware key and the same inputs, you can always reproduce the same password. Nothing is stored locally.

Current status:

* Python CLI, pre-release v0.9.0

* Tested only on Windows 10 with RSA4096 keys

* Requires GPG installed

* English default + Chinese i18n (basic)

Limitations:

1. Not audited (research/PoC)

2. Only RSA tested

3. No GUI (TUI planned)

4. Not tested on other platform

5. Some sites may reject the generated charset (You can edit, but it may cause a mess.)

Looking for feedback on:

1. Security flaws in this design?

2. Portability to Linux/macOS and non-RSA keys

3. Possible ways to use hardware keys without shelling out to GPG

4. Usability / UX ideas (TUI, i18n, etc.)

Links:

GitHub: https://github.com/biliyoyo520/paasword/

Blog: https://blog.yoyo250.fun/archives/coding/16.html

Thanks!

An AI system to help scientists write expert-level empirical software

https://arxiv.org/abs/2509.06503
1•Rudybega•2m ago•1 comments

Dynamic Pricing in Your Pocket

https://www.beyondpricing.com/blog/beyond-mobile-app-launch
1•thomcrowe•4m ago•1 comments

Layout Guidelines

https://marioaguzman.github.io/design/layoutguidelines/
1•speckx•5m ago•0 comments

Btrfs on a Raspberry Pi

https://changelog.complete.org/archives/10852-btrfs-on-a-raspberry-pi
1•jandeboevrie•6m ago•0 comments

Alt-Text as Poetry Website Tour [video]

https://www.youtube.com/watch?v=PUooHXD0JaA
1•xk3•7m ago•0 comments

Compare the New iPhone Models

https://www.apple.com/iphone/compare/
1•skadamat•8m ago•0 comments

Korean Navigation App Turns Road Safety into a Game People Want to Win

https://www.thedrive.com/news/this-korean-navigation-app-turns-road-safety-into-a-game-people-wan...
1•PaulHoule•9m ago•0 comments

Memory Integrity Enforcement

https://security.apple.com/blog/memory-integrity-enforcement/
4•circuit•9m ago•1 comments

Apple Watch Ultra 3

https://www.apple.com/apple-watch-ultra-3/
1•SilverElfin•11m ago•0 comments

How to detect and fix unmapped power infrastructure in OpenStreetMap [video]

https://www.youtube.com/watch?v=gyO93zd30nQ
1•marklit•11m ago•0 comments

Apple Watch Series 11

https://www.apple.com/apple-watch-series-11/
1•SilverElfin•11m ago•0 comments

Apple AirPods Pro 3

https://www.apple.com/airpods-pro/
1•SilverElfin•12m ago•1 comments

Prefab Has Joined Reforge

https://www.reforge.com/blog/prefab-has-joined-reforge
1•tosh•12m ago•0 comments

Amnesty says Pakistan spying on millions through phone-tapping, firewall

https://www.reuters.com/world/asia-pacific/amnesty-says-pakistan-spying-millions-through-phone-ta...
3•ryzvonusef•13m ago•2 comments

Apple expects to notify 100M people that they have hypertension in a year

https://appleinsider.com/articles/25/09/09/apple-expects-to-notify-100-million-people-that-they-h...
3•brandonb•14m ago•0 comments

Judge: Anthropic's $1.5B settlement is being shoved "down the throat of authors"

https://arstechnica.com/tech-policy/2025/09/judge-anthropics-1-5b-settlement-is-being-shoved-down...
4•pier25•15m ago•2 comments

Plex tells users to reset passwords after new data breach

https://www.bleepingcomputer.com/news/security/plex-tells-users-to-reset-passwords-after-new-data...
2•thm•17m ago•2 comments

iPhone 17

https://www.apple.com/iphone-17/
3•tosh•18m ago•0 comments

Apple iPhone 17 Pro

https://www.apple.com/newsroom/2025/09/apple-unveils-iphone-17-pro-and-iphone-17-pro-max/
2•jnieminen•18m ago•1 comments

Apple Watch SE 3

https://www.apple.com/apple-watch-se-3/
2•tosh•19m ago•0 comments

BLS revision shows annual hiring was overstated by 911,000 jobs

https://www.npr.org/2025/09/09/nx-s1-5527000/bls-us-job-growth-numbers-revised
5•manveerc•20m ago•2 comments

AirPods 3 will have live translation and heartrate sensor

https://arstechnica.com/gadgets/2025/09/new-airpods-pro-3-turn-apples-earbuds-into-fitness-tracke...
2•datadrivenangel•20m ago•1 comments

iPhone 17 Pro and iPhone 17 Pro Max

https://www.apple.com/iphone-17-pro/
6•meetpateltech•20m ago•1 comments

Show HN: A text decorator for making text aesthetic with Cool Unicode symbols

https://fontgenerator.now/text-decorator
1•liquid99•21m ago•0 comments

Apple debuts Apple Watch Series 11, featuring groundbreaking health insights

https://www.apple.com/newsroom/2025/09/apple-debuts-apple-watch-series-11-featuring-groundbreakin...
4•excerionsforte•21m ago•0 comments

Apple Debuts iPhone 17

https://www.apple.com/newsroom/2025/09/apple-debuts-iphone-17/
5•excerionsforte•21m ago•2 comments

iPhone Air

https://www.apple.com/iphone-air/
6•gmays•21m ago•1 comments

iPhone Air, a powerful new iPhone with a breakthrough design

https://www.apple.com/newsroom/2025/09/introducing-iphone-air-a-powerful-new-iphone-with-a-breakt...
74•excerionsforte•21m ago•97 comments

Dropbox Paper mobile App Discontinuation

https://help.dropbox.com/installs/paper-mobile-discontinuation
18•mercenario•22m ago•1 comments

Commitment

https://www.hottakes.space/p/on-commitment
1•mooreds•22m ago•0 comments