Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
m8urn
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
10 ms
·
61.
▲
by
m8urn
14y ago
Sorry, I believe being in a day job is patented also.
62.
▲
by
m8urn
14y ago
That is what I am hoping!
63.
▲
Want to Block Common Passwords? Sorry, That is Patented
(xato.net)
110 points
by
m8urn
14y ago
|
65 comments
64.
▲
by
m8urn
14y ago
CloudFlare has saved me a number of times,but when RackSpace had a database error for about 22 hours,the database error wouldn't trigger the cache. I would love to see the ability to trigger on keyword or at least the ability to manually fo
65.
▲
by
m8urn
14y ago
"100 mutations seems high" JTR has more than 180 rules, so I don't think 100 is an unfair number. And yes, mutations do slow down typing which is why I most often use a random non-word that sounds like it would be a word (i.e., lickering, f
66.
▲
Analyzing the XKCD Passphrase Comic
(xato.net)
5 points
by
m8urn
14y ago
|
2 comments
67.
▲
Despite the Hyperbole, Flame is Kind of Lame
(xato.net)
1 points
by
m8urn
14y ago
|
0 comments
68.
▲
by
m8urn
14y ago
The difference is that all of these passwords are public knowledge and already published in some form. My compiling these passwords into a single list is different from gathering them directly from the source!
69.
▲
by
m8urn
14y ago
Yep, they won't even let you use "fingernail clippers" as a password.
70.
▲
by
m8urn
14y ago
How do you know I don't already have your password anyway?
71.
▲
by
m8urn
14y ago
I actually did an analysis of that once but I can't seem to find it now. There actually is a pretty big reduction of keyspace (in the billions) but most of it is keyspace you don't want anyway. That is actually why the best policy is to hav
72.
▲
by
m8urn
14y ago
If nothing else, the list itself is long and intimidating.
73.
▲
by
m8urn
14y ago
Has Facebook ever shared that list?
74.
▲
by
m8urn
14y ago
That is due to the cloudflare service. You can actually leave a note, I do follow up on those. Edit: It's a good thing I'm using that too, 108K hits from this in the last four hours. CloudFlare saved my site from 800k requests and 6GB in ba
75.
▲
by
m8urn
14y ago
I have actually kept most of the original data since I started so I could go back and do that if I wanted. There is about 4gb of raw data there.
76.
▲
by
m8urn
14y ago
Thanks for pointing that out, my list comes from public sources.
77.
▲
by
m8urn
15y ago
There's no reason to think the story isn't true either. This is exactly the same scenario thousands have experienced over the years. Google sends the first automated e-mail, the user appeals, then gets a second canned response from Google.
78.
▲
by
m8urn
15y ago
Yes, Use Bcrypt. And Scrypt: http://news.ycombinator.com/item?id=3725284
79.
▲
Yes, Use Bcrypt. And Scrypt.
(xato.net)
2 points
by
m8urn
15y ago
|
0 comments
80.
▲
by
m8urn
15y ago
Right, and this is what has caused millions of people to panic today and realize that Google really can't be trusted with our data. If someone hacks you and does something with your account, or even if you just do something stupid, years of
81.
▲
by
m8urn
15y ago
When someone violates adwords and adsense TOS they don't get everything banned, just access to those services. In fact I think that is the case with many Google services. I once had an unused youtube account banned for an unknown reason but
82.
▲
by
m8urn
15y ago
What's really the interesting story is that it isn't 2005 and yet this stuff still works.
83.
▲
by
m8urn
15y ago
It may not be a representative example, especially when you consider corporate and banking password policies, but it does show how lame people will be if allowed to set passwords without restrictions.
84.
▲
by
m8urn
15y ago
I wrote a recent blog post that explains the sources: http://xato.net/passwords/how-i-collect-passwords