4 ms·
This is a fascinating premise. I wonder what "02rcV@gwBiE14N2e" says about me... It should go without saying, but don't use your regular password for this site
by dickfickling 9y ago
This is a fascinating premise. I wonder what "02rcV@gwBiE14N2e" says about me...
It should go without saying, but don't use your regular password for this site. There's no way they're using a unique salt for every password in their database, because otherwise it'd be impossible to match people based on the password. Without a unique salt, they're much more vulnerable to a rainbow table attack.
- kazet 9y agoYes, I am not using salt to decrease the time complexity of matching people. And I do agree that using your regular password here is a terrible idea :-)
- vtange 9y agoWouldn't that effectively render the whole 'matching people based off the passwords they hold dear' premise pointless then?
- pcmonk 9y agoThey could definitely use a unique salt if they just check for matches on registration, login, or password change (when they have it in plain text). Still insecure because then you have the info that two different salted passwords have the same plaintext.
- scoot 9y agoBut then what would they match it against?
- jstanley 9y agoIt seems to be looking for exact matches only, so a linear search against the entire user list should be fine, and should quite comfortable be adequate even for thousands of users, depending on hashing algorithm.
- joshuahutt 9y agoBut the rest of the passwords wouldn't be in plain text...
- jstanley 9y agoBut you know the password that has just been entered. Iterate over every hashed password. Hash the plaintext password you know, using the salt from the hashed password. If it's a match, record that the 2 users matched. Loop to next hashed password. If they were plaintext it wouldn't need a linear search because the column could be indexed.
- scoot 9y agoHashed and salted.
- Alex3917 9y agoIf you have a 'regular password' it's already game over.
- taoistextremist 9y agoWhat is a "regular password" in this context? For anything I'm concerned for the security of, I use a unique password, and for other things (accounts for job applications, my accounts on sites like Duolingo, Coursera, and others that I don't spend money on), I use the same password. I can't think of why I'd reuse a password for an account I actually care about.
- anonytrary 9y agoIt is an interesting premise but the more I think about it, the less I am impressed in the password aspect. I feel as if this reduces to the N = 1 case of: Ask N questions to all participants, match those that answer similarly for the most questions. Why would you only ask a single question to determine best matches? And why would that question be of your password? Taking into account more information can only be better for matching people, right?
- jakobegger 9y agoThat’s basically the concept of OKCupid. Unless they’ve changed it in the last ten years or so.
- krisives 9y agoDoes this mean people using password generators will never meet anyone?
- twothamendment 9y agoYou an have security or a date, but not both.
- stephengillie 9y agoThe Romantic Uncertainty Principle
- BrandoElFollito 9y agoIt says that you use a password manager and did not try to invent a slick password to be someone else. So if you also were a woman in her 30-40, fair hair, sporty, liked art and science, did not like to travel, liked spending time with friends or code - you would be a great match. Otherwise nice password!