HN user

markhemmings

659 karma

[ my public key: https://keybase.io/mhemmings; my proof: https://keybase.io/mhemmings/sigs/7BkhXPNWmr2KA4bxYjmostAaSiXjb-BNLdia_yaZ5ZY ]

Posts22
Comments9
View on HN
www.youtube.com 11y ago

The Kids' Guide to the Internet

markhemmings
2pts0
www.digitalocean.com 11y ago

New Features to Europe: IPv6, Private Networking, CoreOS – DigitalOcean

markhemmings
3pts0
www.netneutrality.com 11y ago

Net Neutrality: Join the Fight with Namecheap

markhemmings
1pts0
airtype.io 11y ago

AirType

markhemmings
3pts0
www.getsafeonline.org 12y ago

UK government's password checker sends plaintext password in the URL over HTTP

markhemmings
226pts114
spellup.withgoogle.com 12y ago

Spell Up: A Chrome Experiment

markhemmings
23pts19
blogs.office.com 12y ago

.NET and JavaScript libraries for Office 365 APIs | Office Blogs

markhemmings
2pts0
github.com 12y ago

Atom: free and open source for everyone to download

markhemmings
41pts9
digitalocean.uservoice.com 12y ago

Digital Ocean to Finally Get a UK Datacentre

markhemmings
1pts0
www.digitalocean.com 12y ago

Easily Transfer Snapshots Between Accounts | DigitalOcean

markhemmings
2pts0
lazerwalker.com 12y ago

Literally, A Browser Extension

markhemmings
1pts0
www.bbc.co.uk 12y ago

Entrepreneurs reveal their failures en route to success

markhemmings
1pts0
wordpass.io 12y ago

WordPass – Hate passwords, love passphrases

markhemmings
23pts51
www.bbc.co.uk 12y ago

Heartbleed Bug: Public urged to reset all passwords

markhemmings
8pts2
www.raspberrypi.org 12y ago

Raspberry Pi Compute Module

markhemmings
356pts113
pesticide.io 12y ago

Pesticide – Kill Your Css Layout Bugs

markhemmings
2pts0
play.google.com 12y ago

DCentral 1 by John McAfee – Android Apps on Google Play

markhemmings
2pts0
cssdeck.com 12y ago

CSS 3D Clouds

markhemmings
2pts0
blog.cloudflare.com 12y ago

Cloudflare SSL Vulnerability Fixed (even if they don't admit it)

markhemmings
1pts0
en.wikipedia.org 12y ago

ISO Standard for Storing Gender in Databases

markhemmings
2pts0
twitter.com 13y ago

Huge Spam Attack Trending on Twitter ("How to lose 20lbs")

markhemmings
15pts7
www.bbc.co.uk 13y ago

Feed your pet from your phone

markhemmings
1pts0
Emoji One 12 years ago

Epic how quickly that XSS vulnerability was fixed. Great work guys!

True, account should be disabled after x number of bad guesses. But securing against a "brute force" attack for me is more a case of cracking hashes from a db dump. It's easy to churn though vast numbers of hashes in no time at all these days. Here things like hashing algorithm speed, number of iterations, unique salting and original password length all have a part to play.

Completely agree. For example, I use two-factor authentication on all accounts that allow me to. Regarding limiting to 12 characters, the sites in question there are putting there users at risk and it's very likely they aren't storing passwords correctly, leaving anything you put in that password box vulnerable anyway.

It was a larger number at first, but try remembering say 10 words in a row over a long period of time; most people find that difficult. If hashing is implemented properly (i.e. is slow with a large number of iterations) then passphrases shouldn't have to be that long. And if it isn't, then pretty much anything you use will be as bad as each other (Some people are still using MD5 for example!!) :)

I'm the guy who originally contacted Troy Hunt about this, as he mentions in the blog post.

What annoys me is I'm a very young developer, and I've only really just become interested in security (12 months ago I didn't even know what hashing was!!!), yet there's developers out there with years and years of experience making huge sites for the likes of Tesco and TopCashBack for vast sums of money and they don't think about incorporating even the simplest foundations of internet security a novice like me would implement without even thinking! How is this possible?! If I'm doing it in tiny little php sites with 1 unique visitor ever, why are these 'experts' not in there huge corporate sites with hundreds of thousands of users a month?!

Good question. Why doesn't chrome decompress it when their header suggests they will? Yes it's unneeded and discouraged, but if developers do send gzipped content such as images (which as we all (including the blogger) know, they definitely shouldn't!) surely chrome should just go ahead and decompress it as normal?