Live data from Hacker News

Viewing profile — markhemmings

markhemmings

HN member
Joined
Tue, Aug 14, 2012, 10:43 AM UTC
HN karma
659
Public activity
37 items

About markhemmings

[ my public key: https://keybase.io/mhemmings; my proof: https://keybase.io/mhemmings/sigs/7BkhXPNWmr2KA4bxYjmostAaSiXjb-BNLdia_yaZ5ZY ]

Recent public activity

  1. story
  2. story
  3. story
  4. comment
    Comment #8303753

    Epic how quickly that XSS vulnerability was fixed. Great work guys!

  5. story
  6. story
  7. story
  8. comment
    Comment #7845876

    My initial thoughts are just why not do this client side using javascript? No need for the string to leave the client.

  9. story
  10. story
  11. story
  12. story
  13. story
  14. story
  15. story
  16. story
  17. story
  18. comment
    Comment #7587254

    I agree with and applaud the use of seriously here ;)

  19. comment
    Comment #7587242

    True, account should be disabled after x number of bad guesses. But securing against a "brute force" attack for me is more a case of cracking hashes from a db dump. It's easy to ch…

  20. comment
    Comment #7587201

    Completely agree. For example, I use two-factor authentication on all accounts that allow me to. Regarding limiting to 12 characters, the sites in question there are putting there …

  21. comment
    Comment #7587178

    It was a larger number at first, but try remembering say 10 words in a row over a long period of time; most people find that difficult. If hashing is implemented properly (i.e. is …

  22. story
  23. story
  24. story
  25. story