Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
mkjones
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
11 ms
·
61.
▲
by
mkjones
14y ago
It's comprised in part of what we observed as the top hundred or so user passwords, so I'm hesitant to share it. I hope to do a more in-depth post about some stats we're able to run on password usage - I'll see if it makes sense to disclos
62.
▲
by
mkjones
14y ago
Facebook does - we have a blacklist of common passwords, and you cannot register an account with them or change your password to them. That being said, I think with sufficient protections against brute forcing, password complexity requireme
63.
▲
by
mkjones
14y ago
Do you have a reference for people doing an online brute force attack in the RSA attack? IIRC the only brute forcing they did was offline (i.e. cracking hashes that they had locally). Or maybe that's what you were saying, and I'm just misu
64.
▲
by
mkjones
14y ago
I'm curious what you mean by that. I work on security at Facebook (and actually help with the system that detects malicious logins), and think we have a pretty good / secure login system, even compared to a lot of banks. The odds of a phis
65.
▲
by
mkjones
14y ago
We only store hashes of your previous passwords - we never store them in plaintext. We don't have the ability to enforce a silly requirement like "none of the n grams in a new password can be the same as those in an old password."
66.
▲
by
mkjones
14y ago
Worth clarifying: there's nothing about Facebook Credits involved, and we don't collect any financial information. (I work at Facebook with the team that set this up.)
67.
▲
by
mkjones
14y ago
> Google claimed "patents are wrong, hurt innovation" -- and look at the very same people squeezing every last dollar out of their patent portfolio now, when they have some. How is Google squeezing every last dollar out of their patent
68.
▲
by
mkjones
15y ago
Did anyone look at the linked site http://xato.net/passwords/more-top-worst-passwords ? I pulled his top 10k list, but it doesn't add up with his analysis. I get that the top 100 passwords only cover 14% of the accounts, not 40%. And th
69.
▲
by
mkjones
15y ago
Pretty sure that all happens on the client (your phone).
70.
▲
by
mkjones
15y ago
I hope we don't lose high school teachers to tech companies. The world needs them much more as teachers.
71.
▲
by
mkjones
15y ago
Sounds like "root my box as a service." As one of the commenters there points out, you can just do this with ssh. Which means you're ssh'ing to a machine you probably control, which means you would have had to install the stuff you want at
72.
▲
by
mkjones
15y ago
Yeah, this is a bit of a pain. We have to something similar for facebook ( https://www.facebook.com/note.php?note_id=10150492832835766 ). There's talk of a meta referrer tag ( http://wiki.whatwg.org/wiki/Meta_referrer ) that would allow o
73.
▲
by
mkjones
15y ago
The bandwidth over time visualization is what makes this most valuable to me vs. normal wireshark. It made debugging the differences between two different "internet speed test" sites a lot easier (higher latency = slow-start takes longer =
74.
▲
by
mkjones
15y ago
You should try Comcast's business class service. No bandwidth caps, immediate customer service, and not too much more expensive (especially if you can negotiate a deal through your employer).
75.
▲
by
mkjones
15y ago
Ah yes, I misread your post. The trouble with that approach is that you have to enumerate the dangerous params, and if the actual page URL needs a private parameter to work, you can't get rid of it.
76.
▲
by
mkjones
15y ago
On sites where there's private information in the URLs + links to external sites, overriding the referrer is necessary in order to protect users' privacy / identity. See https://www.facebook.com/notes/facebook-engineering/protecti... for
77.
▲
by
mkjones
15y ago
I don't think url shorteners really hurt referrers at all. They typically use 301 or 302 redirects, which preserve the original referrer.
78.
▲
by
mkjones
15y ago
Isn't that exactly what Quora is doing?
79.
▲
by
mkjones
15y ago
If you don't trust your ISP, this doesn't really improve security at all. If anything, it gives them a choke point which makes it easier to inject content or slurp your data.
80.
▲
by
mkjones
15y ago
You can ask to watch them having sex. They have nothing to hide, right?
81.
▲
by
mkjones
15y ago
How is it heteronormative? I see no reference to the gender that he's interested in.
82.
▲
by
mkjones
15y ago
Yeah, after it's been fixed the person who discovered it is welcome to post details about what it would allow an attacker to do / see / etc.
83.
▲
by
mkjones
15y ago
Shoot, sorry to hear that. I think our attitude has always been pretty good, but the communications channels a few years ago were just not great or easy to find (it sounds like you were stuck on a "my account was hacked" workflow). We've i
84.
▲
by
mkjones
15y ago
from http://news.ycombinator.com/item?id=3321366 : > I think having a bug bounty program is actually a lot better than the vast majority of sites / vendors that don't even have a whitehat [aka responsible] disclosure program, let alone
85.
▲
by
mkjones
15y ago
I don't think we post any details about the exploit, just the fact that someone reported it (see https://www.facebook.com/whitehat ). Of course, once we've fixed the bug, the reporter is free to write about the exploit, how long it was li
86.
▲
by
mkjones
15y ago
Ah, just realized you're the OP. I don't think there's anything particularly irresponsible about posting an already-public disclosure to HN or other aggregators. It's the first person posting it publicly without first privately disclosing
87.
▲
by
mkjones
15y ago
The idea with responsible disclosure is that you want to maximize safety of the public by incentivizing vendors to fix problems while not letting malicious actors exploit them: http://en.wikipedia.org/wiki/Responsible_disclosure . Once th
88.
▲
by
mkjones
15y ago
Glad you like it! $500 is actually just the base bounty - I've seen payouts for quite a bit more depending on how nasty the bug is. At least for me personally, it's not the posting of one person's private photos that is most frustrating -
89.
▲
by
mkjones
15y ago
Thanks, we'll take a look. In the future you should use https://www.facebook.com/whitehat/ though, as I unfortunately don't catch every HN comment :-).
90.
▲
by
mkjones
15y ago
This was indeed a bug, and shouldn't work any more. We turned off the system that lets you report content through this flow (and thus made this bug's code inaccessible) as soon as we became aware of the issue. In the future, if you find a s
More ›