Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I think it would be enough to get hold of the 1,000,000 most common passwords and tell the user it's not allowed.


That still leaves you open to side-channel attacks, yes? It's easy for an attacker to find which passwords are prohibited, so by restricting them you remove them from the search space. But your users aren't going to start choosing fundamentally secure passwords, the attack just shifts to the next 1,000,000 common passwords.


Maybe it just shifts to the secure password you generate and suggest to them?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: