Live data from Hacker News

I mean, why not tell everyone our password hashes?

theobsidiantower.com

1–10 of 167 posts

Re: I mean, why not tell everyone our password hashes?

#3

That inspired this idea: make all password databases public, in an encrypted form. Just post them in a standard location. This is to get rid of the fiction that these are ever private and to eliminate an incentive to break in.

Make it blockchain-based, and you'll likely have some VC funding by tomorrow morning.

Re: I mean, why not tell everyone our password hashes?

#7
post #6

That inspired this idea: make all password databases public, in an encrypted form. Just post them in a standard location. This is to get rid of the fiction that these are ever private and to eliminate an incentive to break in.

Collisions?

A non-issue with salts.

Re: I mean, why not tell everyone our password hashes?

#9

That inspired this idea: make all password databases public, in an encrypted form. Just post them in a standard location. This is to get rid of the fiction that these are ever private and to eliminate an incentive to break in.

> make all password databases public, in an encrypted form

That is a terrible idea because agencies like the NSA or GCHQ with unfathomable resources and techniques will crack them and never tell anyone. Then you'll have a compromised account, the provider won't know, the user won't know. Then the agency would be able to compromise the account a publish whatever they wanted as that identity.

Given there are tricks to mask an IP address, or they straight up tap the wires, that's a #1 way to character assassinate any dissident or someone who they dislike.

> This is to get rid of the fiction that these are ever private and to eliminate an incentive to break in.

And why do you assume criminals wouldn't also try to gain access to the systems? Passwords aren't typically the valuable information in a system, they're there to protect the more valuable data.

Re: I mean, why not tell everyone our password hashes?

#10

That inspired this idea: make all password databases public, in an encrypted form. Just post them in a standard location. This is to get rid of the fiction that these are ever private and to eliminate an incentive to break in.

Make it blockchain-based, and you'll likely have some VC funding by tomorrow morning.

Who wants VC funding when you can raise 8 figures in an ICO! /s
Post reply on HN