Viewing profile — markhemmings
markhemmings
HN member- Joined
- Tue, Aug 14, 2012, 10:43 AM UTC
- HN karma
- 659
- Public activity
- 37 items
- HN profile
- View on Hacker News ↗
About markhemmings
Recent public activity
- story
- story
- story
-
comment
Comment #8303753
Epic how quickly that XSS vulnerability was fixed. Great work guys!
- story
- story
- story
-
comment
Comment #7845876
My initial thoughts are just why not do this client side using javascript? No need for the string to leave the client.
- story
- story
- story
- story
- story
- story
- story
- story
- story
-
comment
Comment #7587254
I agree with and applaud the use of seriously here ;)
-
comment
Comment #7587242
True, account should be disabled after x number of bad guesses. But securing against a "brute force" attack for me is more a case of cracking hashes from a db dump. It's easy to ch…
-
comment
Comment #7587201
Completely agree. For example, I use two-factor authentication on all accounts that allow me to. Regarding limiting to 12 characters, the sites in question there are putting there …
-
comment
Comment #7587178
It was a larger number at first, but try remembering say 10 words in a row over a long period of time; most people find that difficult. If hashing is implemented properly (i.e. is …
- story
- story
- story
- story