|
|
|
|
|
by jstanley
2966 days ago
|
|
A timestamp would work the same way it works in (e.g.) Google Authenticator. Incidentally, I really resent how it's impossible to have a discussion of anything at all related to cryptography on HN without somebody bringing up the "never roll your own crypto" dogma. If the ideas being proposed are bad, please point out why, don't just imply that everyone except you is too stupid to understand. Edit: I just reread your comment above and you did a perfectly good job of explaining why it's a bad idea, I must have misunderstood first time round: it's a bad idea because now the login credentials get compromised in a database leak instead of a MITM, which is both more common in practice and affects more users at once. Sorry for saying you didn't explain why it is a bad idea. |
|