Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

That's the trouble... the "sensible" options aren't so sensible when you really sit down and think about how they can be dodged, broken or abused.

Imagine I'm trying to crack into your site, and you lock any account after 5 failed logins in a row.

If I have access to (or can guess) a few thousand usernames, I can try the 4 most common passwords on all of those with no problems. I'll probably get some hits, no?

Or heck, I can try the 5 most common passwords, and not only will I have a few hits, I'll also have plenty of time to dig around without any attention from you, because you'll be struggling with a massive customer service nightmare, as thousands of your customers find themselves all locked out the same morning.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: