Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
woobles
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
4 ms
·
1.
▲
by
woobles
13y ago
https://www.duosecurity.com/authentication-methods What? This exists...
2.
▲
by
woobles
13y ago
This seems like simplicity just for simplicity's sake...
3.
▲
by
woobles
13y ago
Look at that Wikipedia article under "Multiquines"
4.
▲
by
woobles
13y ago
I will be very interested to see how this story develops in the coming days/weeks. Clever of these services, pitting State v. City.
5.
▲
by
woobles
14y ago
Yes, they did, and Turing was chemically castrated. Not by the baddies, either. It might not be going to war to die, but that is still pretty messed up.
6.
▲
by
woobles
14y ago
No. Query parameterization is how you avoid this. How do you propose that encryption would prevent SQL Injection?
7.
▲
by
woobles
14y ago
Encryption encryption encryption.
8.
▲
by
woobles
14y ago
This does seem to be a logical argument, these days. :/
9.
▲
by
woobles
14y ago
The article specifies that many people targeted used emails unique to their dropbox accounts.
10.
▲
by
woobles
14y ago
That's JSUT what they want you to think!
11.
▲
by
woobles
14y ago
Fair enough. My numbers are of course based on an unsalted hash which has been stolen from a db or otherwise obtained by an attacker. Further arguments include high overhead for learning (not to mention changing passwords) a given password,
12.
▲
by
woobles
14y ago
I remain unconvinced that anything would assuage his paranoia, unfortunately.
13.
▲
by
woobles
14y ago
One of my old bosses thought that all Lenovos possessed BIOS-level malware that could be activated at a moment's notice by the Chinese government should the US ever got to war with them. He was a weird dude.
14.
▲
by
woobles
14y ago
Very interesting. Thanks!
15.
▲
by
woobles
14y ago
I would personally prefer to have my password at any time, rather than have to get in the "zone" to authenticate into my computer.
16.
▲
by
woobles
14y ago
While this does sound interesting from a psychological/neurological perspective, I feel bad for anyone who actually tries to implement a password system based on this. 38 bits of entropy is nothing, a standard password with 38 bits of entro
17.
▲
by
woobles
14y ago
I'm going to assume you mean "What tools can a web entrepreneur use to check if his site can be hacked by script-kiddies". There are a multitude of static analysis and penetration testing tools out there, free and licensed. Fortify (Static
18.
▲
by
woobles
14y ago
Ah yes, that makes sense. I'm not terrific at business sense, thanks. I had not considered that targeting existing Yahoo customers doesn't necessarily cannibalize Google's customers, since they're clearly not jumping to move to gmail, are t
19.
▲
by
woobles
14y ago
I think a big part of the problem is that, were Yahoo! to enter the phone game now, they'd be years behind their competitors. iOS, Android, BlackBerry, and Windows mobile are all pretty established, and could all easily out-maneuver a new c
20.
▲
by
woobles
14y ago
An evercookie is actually pretty straightforward to remove, if you know what you're doing with firebug/firecookie. The only tricky thing it does is persist a cookie in the sessionStorage of your window object, which isn't cleared when you c