3 ms·
> the impact of this type of attack on the end-user can be almost entirely mitigated by using unique passwords on each site which unfortunately isn't going to
by brey 13y ago
> the impact of this type of attack on the end-user can be almost entirely mitigated by using unique passwords on each site
which unfortunately isn't going to happen.
the bigger point missed by the article is that this reliance on 'correct' usage isn't even necessary if the hashes were created in the right way - properly salted (per-user, not just a static string for the site) and using a tunable computationally intensive hash algorithm like bcrypt or scrypt.
- bradleyjg 13y agoThat's something that only the site programmer can do, and end users have no control or even insight into. If the article is aimed at developers, I agree with what you are saying (see the last line of my post). But it reads to me like it's aimed more at users. If that's true they should emphasize the best thing that users can do to protect themselves -- which is not using the same password in more than one place. Or they could have done both, instead of neither.
- hrktb 13y agoTo throw that in, there's a whole category of site that use a plain text password that can be checked by phone/re-sent back to you/printed on some statement. While from a best practice point of view it's sub standard, the use case can be legit (in the best case your password only helps to discloses minor-ish info, and the service value is purely IRL), and you might not know in advance that they don't intend to keep your password any much safer. You have to accept that there will be plenty of online service that won't try to keep high online security and you'll have to use not too complicated, throwable passwords for every site that don't have enough stakes in protecting your auth data (I'd say basicly anything that's not monney and mail related)