3 ms·
> it doesn't really hurt me any This is the unsafe mentality of "roll your own" and it's always a bad idea. There's a reason why we have to practically blindly
by vmasto 10y ago
> it doesn't really hurt me any
This is the unsafe mentality of "roll your own" and it's always a bad idea. There's a reason why we have to practically blindly follow the best practices; the attack vectors are so diverse we cannot predict them.
How would you handle 3rd party phishing schemes attempting to register users with weak passwords for example?
- novaleaf 10y agoAs I said, I use recaptcha to prevent bots, which would also include preventing phishing. Ultimately, if you are writing A SaaS you have to roll your own at some point, but I agree it shouldn't include things like key derivation functions. Maybe I'm dense, but I just don't see how enforcing password strength on both the client and server is making me safer from hackers.