4 ms·
Rule n1: don't roll your own security. Rule n2: goto 1 You are overcomplicating your authentication system by oversimplifying security problems and the result
by professorTuring 9y ago
Rule n1: don't roll your own security.
Rule n2: goto 1
You are overcomplicating your authentication system by oversimplifying security problems and the result is that you have solved nothing.
Security always seems very easy to solve and usually non-security engineers tends towards solutions like yours that doesn't provide extra security, they just add a few extra steps for a hacker to obtain you database and as a result you need to maintain extra databases, there are more error points... Do you remember that thing about "each extra system exponentiates complexity"?
- odammit 9y agoYou don’t have to “roll your own security.” You can easily put any open source security system behind a secondary system. Hell - it would already be a secondary system. Not putting your passwords right next to the identifiers is a simple way to lower the impact of an email or password leak. Also, that quote is bullshit.
- professorTuring 9y agoMeh... I won't bother. Discuss your solution with a security guy you trust.