4 ms·
Author doesn't understand problem space at all. 1) Weak passwords are not ok even on throw-away accounts. Just because you have no use for it, doesn't mean nob
by Tractor8626 2y ago
Author doesn't understand problem space at all.
1) Weak passwords are not ok even on throw-away accounts. Just because you have no use for it, doesn't mean nobody has. Sending spam, or impersonating you or some other creative use.
2) Nobody is going to bruteforce your password. We don't use md5 anymore. You password will get stolen. By phishing, malware, social engineering, password reuse etc.
- einr 2y agoBy your own argument, if no one is going to bruteforce your password, what then is the issue with a weak password?
- Jnr 2y agoPassword lists are full of weak passwords. You don't brute-force the password, you use a password list instead.
- notpushkin 2y agoPotato, potato. Does anybody really say “bruteforce” not meaning a dictionary attack?
- janalsncm 2y agoThe author of the article, apparently.
- Krutonium 2y agoYes, plenty. It's not great for passwords, (but sometimes it still is! Sometimes sites using MD5 still get popped) but there's plenty of other problem spaces where brute forcing still means brute forcing.
- notpushkin 2y agoSorry, forgot to clarify! Yeah, the context matters here: if you’re cracking something like a numeric PIN, or looking for something like a hash collision, you might want to iterate through all possible solutions, randomly or sequentially.
- giantrobot 2y agoCredentials stuffing. Attackers can spam a site with logins with common passwords. Too few sites implement good mitigations against this because it's easy to block/lock legitimate users that typoed a password.
- tracker1 2y agoThis is why I isolate authentication to a separate application. I also implement max attempts per N minutes for IP and User. Most users once authenticated are good for the work day. Auth going down doesn't (generally) affect the work.
- deleted 2y ago[deleted]
- arkh 2y ago> Just because you have no use for it, doesn't mean nobody has. Lot of websites you'll visit once per decade (maybe) still ask for account. Or things like the software you get to manage your gaming peripherals which nowadays all ask for an account for no reason. Those accounts getting hacked? I don't care. So they all get a shitty birthday password if they accept it. If they prefer to use some stupid "X uppercase, Y lowercase, Z numbers, some special characters" I'll make a new account next time because I'm not using a real email. Or just stop there.
- wvh 2y agoThat is your perspective. Not that of the site owner, or the internet at large, victim to any abuse somebody unkind can unleash. Security is a bit like traffic. If you're alone in the world, you do you. But you are not alone, you have a responsibility to others, be it passers by, fellow travellers or those loved ones depending on you making it back alive.
- ss64 2y agoIf a new account has that much power to abuse the system, then your problem is not the 2FA security. They don't need to crack your account, a bad actor could just create a new account for themselves.
- Macha 2y ago> That is your perspective. Not that of the site owner, or the internet at large, victim to any abuse somebody unkind can unleash. Frankly, in a lot of these cases the site owner (e.g. Razer) has already decided to put their interest ahead of mine by requiring accounts to e.g. configure peripherals locally so they have can harvest sign ups for their marketing lists or tell investors they have XXX MAUs. I don't care if my password choice inconveniences them in turn.
- janalsncm 2y agoSounds like you’re describing a situation where every user must have a secure account in order avoid a problem. In that case, it’s not just the technically-minded folks here who need to have secure passwords. The site itself should enforce password security, not individuals.
- TeMPOraL 2y ago> 1) Weak passwords are not ok even on throw-away accounts. Just because you have no use for it, doesn't mean nobody has. Sending spam, or impersonating you or some other creative use. Why should that be my problem? It reeks of the same bait-and-switch that banks are doing, with calling failures of their lax KYC/security process "identity theft", calling themselves the victim, and making the actual victim responsible for it.
- zugi 2y agoI love this, yes the crime of getting a loan with stolen or fake credentials used to be called "bank fraud" and it was the bank's problem. Now it's called "identity theft" and they've convinced many of us it's our problem. So much that people pay the banks to buy "identity theft protection"!
- croes 2y agoDepends on the purpose of the account. For instance this requires an account https://news.ycombinator.com/item?id=43245361 https://news.ycombinator.com/item?id=43245361
- autoexec 2y ago> Weak passwords are not ok even on throw-away accounts. They can be okay for throw-away accounts, it just depends on the circumstance. > Nobody is going to bruteforce your password. I can assure that there are still people brute forcing passwords. I see it happening all the time, especially for SSH accounts. While you are correct that phishing and password reuse are problems, they are also not totally solved by using 2FA.
- tigereyeTO 2y agoAuthor also confuses backup codes with TOTPs.
- sam_lowry_ 2y agoOP here. It's a typo and should read OTP. This accidental confusion between TOTP and OTP is by itself an argument against complex alternatives to login+password.