HN user

moakakala

17 karma
Posts0
Comments8
View on HN
No posts found.

I think the site/service is pretty slick and well-made. It worked well for me -- I'd be curious to see what kinds of boxes these people failing were drawing (or whether it's just a browser issue for them or something).

These comments are all pretty negative, and I think the criticisms are mostly valid, but I don't think you've made a bad product (though it may need some tweaking, and captchas may be on their way out now for the reasons others have posted).

I just know that I've felt awful before when receiving similar comments to these others, and I would have liked someone to remind me: you made something pretty good, and it wasn't a stupid idea.

> If you want to save the world, save the world first. > Stop. Fucking. Waiting.

I don't understand what you're suggesting. Is Trigg (the programmer who joined Wall Street) "waiting"? What does "not waiting" look like?

>Also, out of curiosity, in his timing attack example, the difference in time caused by the string being equal seems like it'd get absolutely swallowed up by the random nature of the universe - do those things actually work in the real world, on real servers with varying loads and numbers of users and network traffic?

You could make each request many times, and then average them together. I don't know how many requests you'd have to make to overcome the random fluctuations though -- probably a lot.

> This means that as long as you have one example of a signed message, you can forge signatures for that message plus any arbitrary request parameters you like and they will authenticate under the above described scheme.

If all requests are made over HTTPS, how could a third party intercept a signed message? How is this any greater of a risk than a third party intercepting user login information? (This is a serious question; I'm not being flippant or saying 'gotcha')