3 ms·
I wasn't advocating for blindly using SSL, only to fix things short-term. Long-term I'd hope for better handling of passwords. This isn't a huge deal to me, I
by theonewolf 14y ago
I wasn't advocating for blindly using SSL, only to fix things short-term.
Long-term I'd hope for better handling of passwords.
This isn't a huge deal to me, I just want a warning out there for people to use throwaway passwords.
- coderholic 14y agoBetter handling how exactly? Either you send a login token over the wire in plain text, or you send it over HTTPS. It makes no difference if you hash client side or not, as it's still a login token that can be sniffed and reused. Even sniffing is only really likely to be a problem if you're on a public wifi network. It seems like you're blowing this out of all proportion. It was only relatively recently that Facebook starting forcing HTTPS for authentication, and many many sites (inc. HN) still don't.
- paulgb 14y agoI think the point is that if the password is one that's used elsewhere, if it's client-side encrypted, at least it can't be captured for use on another site by an eavesdropper. It does nothing against an attacker who can get in the middle of the transmission though.
- paulgb 14y agoI'm not talking about blind use of SSL, I'm saying users should always be cautious with their password. The burden of protecting your bank password falls on you, if you're using it on a third-party site, SSL or not, you're at risk.
- theonewolf 14y agoI think we all know this is unfeasible. I don't think we can expect the general public to even be _acquainted_ with acronyms like SSL; or an understanding of why passwords need to be completely different. And this is a startup that hopes to train people in hacking...I was just expecting a bit more on the security-side I suppose. What we can hope to do is place warnings that let them know when things are safer and when not. I guess I haven't followed many launches recently (to see if people are starting things more secure or not). I checked out Hacker Rank because I _really_ like their idea. And hope to let some younger friends (brother etc.) to use the site.
- theonewolf 14y agoThe 8th most dangerous software error (2011 CWE/SANS Top 25 Most Dangerous Software Errors) is not encrypting sensitive data. If they ever want a paid-for version (maybe for future lessons), this will become an issue. I'd just rather bake it in from the beginning.