4 ms·
The problem is that people are signing up and may be using passwords which they do use on a bank website etc. Man-in-the-middle ARP attacks or even just sniffi
by theonewolf 14y ago
The problem is that people are signing up and may be using passwords which they do use on a bank website etc.
Man-in-the-middle ARP attacks or even just sniffing the wire will reveal your password to attached machines on the path from you to HackerRank.com.
- paulgb 14y agoUsers should be trained not to do that. Sure, it's good for the site to use SSL, but training users to look for a lock logo will only protect them from MITM & wire sniffing, not untrustworthy sites.
- theonewolf 14y agoI wasn't advocating for blindly using SSL, only to fix things short-term. Long-term I'd hope for better handling of passwords. This isn't a huge deal to me, I just want a warning out there for people to use throwaway passwords.
- coderholic 14y agoBetter handling how exactly? Either you send a login token over the wire in plain text, or you send it over HTTPS. It makes no difference if you hash client side or not, as it's still a login token that can be sniffed and reused. Even sniffing is only really likely to be a problem if you're on a public wifi network. It seems like you're blowing this out of all proportion. It was only relatively recently that Facebook starting forcing HTTPS for authentication, and many many sites (inc. HN) still don't.
- paulgb 14y agoI think the point is that if the password is one that's used elsewhere, if it's client-side encrypted, at least it can't be captured for use on another site by an eavesdropper. It does nothing against an attacker who can get in the middle of the transmission though.
- paulgb 14y agoI'm not talking about blind use of SSL, I'm saying users should always be cautious with their password. The burden of protecting your bank password falls on you, if you're using it on a third-party site, SSL or not, you're at risk.
- theonewolf 14y agoI think we all know this is unfeasible. I don't think we can expect the general public to even be _acquainted_ with acronyms like SSL; or an understanding of why passwords need to be completely different. And this is a startup that hopes to train people in hacking...I was just expecting a bit more on the security-side I suppose. What we can hope to do is place warnings that let them know when things are safer and when not. I guess I haven't followed many launches recently (to see if people are starting things more secure or not). I checked out Hacker Rank because I _really_ like their idea. And hope to let some younger friends (brother etc.) to use the site.
- theonewolf 14y agoThe 8th most dangerous software error (2011 CWE/SANS Top 25 Most Dangerous Software Errors) is not encrypting sensitive data. If they ever want a paid-for version (maybe for future lessons), this will become an issue. I'd just rather bake it in from the beginning.
- cnlwsu 14y agoRight away they said they are adding HTTPS yet you continue pounding and then broadcast it to the world in HN, seems unreasonable. "just sniffing the wire" will only work if your connected to the same dumb hub, modern switches don't broadcast packets on the subnet. ARP poisoning could force their browser to forward the traffic to you and you can forward it on to the gateway. Even that would require you to be on the same subnet. Once they have HTTPS they are protecting you just as much as any other service. If they refused to support HTTPS I would see this being a problem - but they are not.
- theonewolf 14y agoThe problem is that people are signing up with real passwords today without being warned that they _could_ be being compromised. Yes, _tomorrow_ it might be fixed. But today no one knows there is an issue and their password has been exposed.
- projct 14y agoWi-Fi is common enough that Apple has been dropping Ethernet adapters from products. Sounds like the perfect 'dumb hub' to me!