3 ms·
If you spend the time building a system to search those half billion passwords when you’re users are signing up, you should focus on building a login rate limit
by odammit 9y ago
If you spend the time building a system to search those half billion passwords when you’re users are signing up, you should focus on building a login rate limiting system so it’s not possible to brute force someone’s password.
- royce 9y agoThe purpose of a blacklist is multifold - to reduce the efficiency of an offline attack, in which the hashes are stolen and can be attacked at high speeds without rate limiting - as well as an online attack.
- odammit 9y agoSure and 10k will do fine otherwise “! I thh Cher;457?:25?//(5 we” is going to suck for you user login story. Maybe salt your passwords, use some stretches, and a decent algorithm instead of MD5, SHA1, etc. Also stay up on algorithms and roll your users over to new ones over time.
- ravenstine 9y agoI think this is intended for the case where a database has been compromised, but then again, I thought that hash algorithms and salting were supposed to deal with that.
- MBCook 9y agoIF people actually do that correctly, yes. But history has proven many sites (big and small) are quite happy to send you your plaintext password.
- odammit 9y agoAlthough it does happen that’s amature and unacceptable. Either you have some EXTREME legacy or lazy engineers. Doing it right doesn’t take long.
- rphlx 9y agoThough I agree rate limiting should be done (and done carefully), it is not very effective in all cases. As just 1 example, a determined attacker who wants to pop any account can make 3 attempts on hundreds of thousands of accounts, using a unique IPv4 address per account, thanks to Windows & IoT botnets.
- odammit 9y agoWAF, IP blacklists, naive bot detection[0] and why would a decent thresholding system allow for a single IP to fail multiple accounts in a short time period. If you hit two valid accounts [1] with bad passwords in a few ACCEPTABLE_UNIT_OF_TIME, it’s captcha time. Thresholding isn’t just action per IP it’s being smart about how people are going to attack your system. It requires thought and upkeep. [0] Previous thoughts on bot detection: https://news.ycombinator.com/item?id=16182405 https://news.ycombinator.com/item?id=16182405 [1] Also, if your login identifier and your public “display names” (usernames) are the same thing, that is a disservice to your users’ security.