Hacker News new | ask | show | jobs
by Wool2662 1046 days ago
And yet the likelihood of you telling someone or typing the contents of this file somewhere you shouldn't is much lower. It's more phishing resistant and is much less likely to be in some leaked password database, that's what GitHub cares about. Targeted attacks on single people don't even move the needle.

Phishing and password stuffing attacks are like 95% of 'hacking' attempts.

And frankly it is very likely that your 40 character password landed in your shell history at least once.

1 comments

GH also prefixes them and undoubtedly scans for and invalidates them.

I don't think I ever cringe as much as HN threads with people clamoring for backwards steps for security.