5 ms·
Its really simple , AS LONG AS the user uses a weak password, using bcrypt or not wont protect him. Why ? Well instead of brute forcing the hashed password i'l
by asdfor 16y ago
Its really simple , AS LONG AS the user uses a weak password, using bcrypt or not wont protect him.
Why ? Well instead of brute forcing the hashed password i'll directly try to bruteforce using the normal login method of your site (even if you rate limit my login attempts it wont take that much time...(see proxys)(if you are thinking about rate limiting per username etc you suck).
If you need yours users account to be safe just force them to use a strong enough password
hashed(password + salt) = epic win
- davebob 16y agoplease explain what you mean by rate limiting and why that's no good.
- asdfor 16y agoIn some period of time a user is only able to do some amount of login attempts, after that he has to wait until he can try again to login. You can do that per IP or per username, doing it per username its not good because someone can abuse that to block the genuine user to log in. Doing it per ip is the best option you have and i didn't say that its not good, what i said is that if the user uses a weak password even if you put a rate limit they will be able to find the password soon enough.
- Raphael 16y agoI think rate limiting per user is perfect. And if the real person wants to log in while someone else used up their attempts, do a quick email confirmation.
- asdfor 16y ago"do a quick email confirmation". And what happens if one or more of your users gets targeted for a long period of time ? You will force them to open there inbox every time they want to log in your site ? And this gets even better if they target your site generaly, it will be a lot of fun for the majority of your userbase to have to do that "open inbox" step, bet users will love it :) Sorry mate but your method sounds easily exploitable ... heck using reCaptcha would be less punishing for the user than your approach.