5 ms·
Show HN: A dating app that matches people based on their password
- hood_syntax 9y agoIn order to maximize my pool, should I choose 123... variants? Would I be lowering my chances of success by reducing the median quality of members?
- dickfickling 9y agoThis is a fascinating premise. I wonder what "02rcV@gwBiE14N2e" says about me... It should go without saying, but don't use your regular password for this site. There's no way they're using a unique salt for every password in their database, because otherwise it'd be impossible to match people based on the password. Without a unique salt, they're much more vulnerable to a rainbow table attack.
- kazet 9y agoYes, I am not using salt to decrease the time complexity of matching people. And I do agree that using your regular password here is a terrible idea :-)
- vtange 9y agoWouldn't that effectively render the whole 'matching people based off the passwords they hold dear' premise pointless then?
- pcmonk 9y agoThey could definitely use a unique salt if they just check for matches on registration, login, or password change (when they have it in plain text). Still insecure because then you have the info that two different salted passwords have the same plaintext.
- scoot 9y agoBut then what would they match it against?
- jstanley 9y agoIt seems to be looking for exact matches only, so a linear search against the entire user list should be fine, and should quite comfortable be adequate even for thousands of users, depending on hashing algorithm.
- joshuahutt 9y agoBut the rest of the passwords wouldn't be in plain text...
- jstanley 9y agoBut you know the password that has just been entered. Iterate over every hashed password. Hash the plaintext password you know, using the salt from the hashed password. If it's a match, record that the 2 users matched. Loop to next hashed password. If they were plaintext it wouldn't need a linear search because the column could be indexed.
- scoot 9y agoHashed and salted.
- Alex3917 9y agoIf you have a 'regular password' it's already game over.
- taoistextremist 9y agoWhat is a "regular password" in this context? For anything I'm concerned for the security of, I use a unique password, and for other things (accounts for job applications, my accounts on sites like Duolingo, Coursera, and others that I don't spend money on), I use the same password. I can't think of why I'd reuse a password for an account I actually care about.
- anonytrary 9y agoIt is an interesting premise but the more I think about it, the less I am impressed in the password aspect. I feel as if this reduces to the N = 1 case of: Ask N questions to all participants, match those that answer similarly for the most questions. Why would you only ask a single question to determine best matches? And why would that question be of your password? Taking into account more information can only be better for matching people, right?
- jakobegger 9y agoThat’s basically the concept of OKCupid. Unless they’ve changed it in the last ten years or so.
- krisives 9y agoDoes this mean people using password generators will never meet anyone?
- twothamendment 9y agoYou an have security or a date, but not both.
- stephengillie 9y agoThe Romantic Uncertainty Principle
- BrandoElFollito 9y agoIt says that you use a password manager and did not try to invent a slick password to be someone else. So if you also were a woman in her 30-40, fair hair, sporty, liked art and science, did not like to travel, liked spending time with friends or code - you would be a great match. Otherwise nice password!
- lionheart 9y agoSoooooo... if people use their standard password on this you'll be able to login as them as soon as you get any personally identifiable info - like email or FB account, right?
- psychometry 9y agoThis submitter has basically no history on this site. Smells like a honeypot to me.
- exolymph 9y agoYou'd have to be a moron to use a password that already you use anywhere else. Then again, people are generally morons. (Or, more charitably, they know very little about technology and opsec. Granted, that doesn't seem to be the Hacker News target audience.)
- jonas21 9y agoBut that's the whole point of the site. If I enter a randomly-generated password, how's it supposed to match me with anybody?
- exolymph 9y agoYou could use a password that you feel represents you despite being newly conceived.
- sandov 9y agoYou'd have to be a moron to use your password AND give some other information that can be traced back to you or your accounts by the creator, passwords by themselves are practically useless.
- jstanley 9y agoI think you'd have to be a moron to give your password even if you don't knowingly give some information that can be traced back to you. Even if nothing at all traces it back to you, it would be easy to add every received password to a dictionary for later consultation. But besides that, the data can be linked to you if you ever knowingly give any identifying data to another website that the attacker here has control over (or, at least, can observe). If he sets a cookie, or remembers your ip address, or your browser fingerprint, there's every chance that he might later be able to find out your real email address. Do not give your real passwords to this site.
- eptakilo 9y agoThis website seems a little fishy.
- dragonwriter 9y agoI think you misspelled “phishy”.
- zerostar07 9y agophishy
- amelius 9y agoCan I have an app based on 23andme data already?
- ilconsigliere 9y agoSo if I match with someone we now both know each other's passwords?
- krisives 9y agoMeant to be! Also trust!
- JavaOffScript 9y agoThis ensures you can never ever break up.
- whoisjuan 9y agoDoes this mean that they don't hash your passwords? They save it in plain text somewhere? ... Also, this is a terrible idea...
- Miner49er 9y agoNo, they can still hash it. Just not with unique salt, I believe.
- deleted 9y ago[deleted]
- alasdair_ 9y agoSeems like a really bad idea for a honeypot.
- Santosh83 9y agoI use entirely random, machine generated passwords. I assume my matches would also be similarly random?
- SmooL 9y agoWell, random only in the set of people who use machine generated password!
- zerostar07 9y agothis must be the first polyamory matchmaker. the '12345678' village and the 'password' megacity are waiting just around the corner
- Exuma 9y agocamaro69... is that you???
- anfractuosity 9y agoHaha. You could use something akin to the principle behind the Socialist millionaires problem, to compare two values without revealing them to another party.
- Jenkins2000 9y agoThis would be a great addition to my other sites. One finds matches based on your mothers maiden name, and the other finds matches based on your social security number.
- wink 9y agoI don't care if it's a honeypot, it's the best laugh I had today. Also, I'd be so interested in a large-scale study if this single data point correlates with anything.
- purplezooey 9y agoY'all could just use a previous password.