Live data from Hacker News

Sending spammers to password purgatory

troyhunt.com

81–90 of 170 posts

Re: Sending spammers to password purgatory

#81
post #13

I assume your starting password rules deliberately set the bar low to encourage PRs to improve it, since I can think of much more believable, infuriating, tedious ways to drag this out longer, keeping the user thinking they're always one step away from a valid password without being obviously silly. Believable, stupid requirements I've seen in the wild in the bad early days of complexity requirements. - your password…

Hah... this reminds me of the following (perhaps most interesting for people speaking german): Bitte geben Sie ein sicheres Passwort ein. Leberkas Entschuldigung, Ihr Passwort ist zu kurz! Leberkas-Semme Entschuldigung, Ihr Passwort muss mindestens 1 Zahl enthalten. 1 Leberkas-Semme Entschuldigung, Ihr Passwort darf keine Leerzeichen enthalten. 50drecksleberkassemmen Entschuldigung, Ihr Passwort muss mindestens einen…

You got me at "Entschuldigung, dieses Passwort ist bereits in Verwendung." :D

Re: Sending spammers to password purgatory

#82

This reads a bit much like an ad. I sure have to scroll through a lot about Microsoft, Cloudflare, etc. before the funny password requirements I came for, at the verrrry end.

Yeah especially using that Microsoft service. Takes me back to M$ sponsored tech talks where they had to use MSN search and not mention the G word.

This is a Microsoft sponsored tech talk. Advertising for MS is one of Troy's businesses, as he discloses in his bio on the page. And the banner at the top says this particular post is sponsored by Cloudflare.

Re: Sending spammers to password purgatory

#83

Earlier quoted context omitted.

Legitimate interest would totally cover you here. The fear-mongering and misinformation about the GDPR is getting really annoying by now.

> The "legitimate interest" GDPR strawman In the past three and a half years I have witnessed four cases in which this exact method (cross-linking remote IP addresses to detect spammers/attackers/bots/etc.) has been an issue with GDPR, but I am sure those downvotes and the general tech-centered HN'y wave-off as misinformation have a better standing in EU courts these days since the fear-mongering GDPR hype is mostly…

Has been an issue in what way?

Re: Sending spammers to password purgatory

#84

Earlier quoted context omitted.

I understand the initial idea to block this known neo-Nazi short handle (8 for the letter H and 88 as HH standing for the 'Heil Hitler' salute in these circles). But how many people do I know born in 88. Or on the 8th of August? I understand that given the login is your public visible name on steam they just don't want clear neo-Nazi signifiers. Edit: Typo

88 is a lucky number in China and many Asian countries. Maybe time to claim “cultural insensivity” or something? Also, steam should never even see the password, they should only ever see the hash.

The real fun starts with IDNs -- internationalized domain names.

- https://en.m.wikipedia.org/wiki/Internationalized_domain_nam...

Re: Sending spammers to password purgatory

#85
post #82

Earlier quoted context omitted.

Yeah especially using that Microsoft service. Takes me back to M$ sponsored tech talks where they had to use MSN search and not mention the G word.

This is a Microsoft sponsored tech talk. Advertising for MS is one of Troy's businesses, as he discloses in his bio on the page. And the banner at the top says this particular post is sponsored by Cloudflare.

I thought that was the case!

Re: Sending spammers to password purgatory

#86

Earlier quoted context omitted.

Legitimate interest would totally cover you here. The fear-mongering and misinformation about the GDPR is getting really annoying by now.

> The "legitimate interest" GDPR strawman In the past three and a half years I have witnessed four cases in which this exact method (cross-linking remote IP addresses to detect spammers/attackers/bots/etc.) has been an issue with GDPR, but I am sure those downvotes and the general tech-centered HN'y wave-off as misinformation have a better standing in EU courts these days since the fear-mongering GDPR hype is mostly…

I often see downvotes for comments that make claims but don't include details.

In this case you say, "an issue with GDPR" but fail to elaborate.

Re: Sending spammers to password purgatory

#87
post #64

Earlier quoted context omitted.

And this would be a new way to attack him

He's triggering it manually. And I'm pretty sure he knows what backscattering is.

I missed the manual part. If that is the case I wonder whose time is getting more wasted!

Re: Sending spammers to password purgatory

#88

Earlier quoted context omitted.

Legitimate interest would totally cover you here. The fear-mongering and misinformation about the GDPR is getting really annoying by now.

> The "legitimate interest" GDPR strawman In the past three and a half years I have witnessed four cases in which this exact method (cross-linking remote IP addresses to detect spammers/attackers/bots/etc.) has been an issue with GDPR, but I am sure those downvotes and the general tech-centered HN'y wave-off as misinformation have a better standing in EU courts these days since the fear-mongering GDPR hype is mostly…

Go on, tell us more so we can do better.

Re: Sending spammers to password purgatory

#89
You can check in their GitHub repo [1] the list of reasons to reject your password (classified by level of "InfuriationLevel"). Some examples:

'Password must contain at least 1 primary Simpsons family character'

'Password must contain at least 1 Nordic character'

'Password must contain at least 1 Greek character'

'Password must contain at least 1 primary Griffin family character'

'Password must contain at least one emoticon'

'Password when stripped of non-numeric characters must be a number divisible by 3'

[1] https://github.com/troyhunt/password-purgatory-api/blob/mast...

Re: Sending spammers to password purgatory

#90
post #61

Earlier quoted context omitted.

I found a surprisingly effective way of detecting honeypots some time ago, while working at an email marketing company.

You have a truly marvelous demonstration of this method, which this margin is too narrow to contain?

Let me guess: honey pots are on all the torrented/darkweb lists of emails that get shared. Regular vics will be on a subset or just one.
Post reply on HN