3 ms·
How else are they supposed to verify your password when you attempt to log in?
by adevine 10y ago
How else are they supposed to verify your password when you attempt to log in?
- username3 10y agoEmail a link with token to log in.
- Skunkleton 10y agoThat is a good way to get endless token links spammed at your inbox...
- username3 10y agoGmail tokens tab.
- stephenr 10y agoSo all of a sudden the service in question's security is only as strong as the security of the client's email service? Yeah that sounds like a big nope to me. This 'idea' has been thrashed out a hundred times, even by supposed 'experts' like Egor Homakov who also says things like "You don't need 2FA, it's pointless and annoying for users".
- sirn 10y agoThere is something like Secure Remote Password (SRP)[1] where it is possible to verify a password without password being to transmitted to the server at all. The problem is, it is tricky to implement, a little bit old, and still vulnerable to bruteforce attack (Blizzard uses it, and IIRC their verifier database was leaked once, with g and N being published, so anyone could do dictionary attack on it. I believe Apple is also using it). [1]: https://en.wikipedia.org/wiki/Secure_Remote_Password_protocol https://en.wikipedia.org/wiki/Secure_Remote_Password_protoco...
- MarkMc 10y agoWe use SRP with our online accounting software [1]. We counter brute-force attacks by using Scrypt for the work factor, and forcing all login credentials to have a high degree of entropy. [1] https://www.solaraccounts.co.uk/ https://www.solaraccounts.co.uk/