Hacker News new | ask | show | jobs
by cced 881 days ago
Force them to change their password, prevent use of the account? If it’s a dormant account, force a password reset using email?

Doesn’t feel like an unsolvable problem, certainly not one without edge cases but surely we can hit 80/20 without too big a hassle.

1 comments

The thing is, attackers don't need 20%. The article says they used 14k accounts with previously cracked passwords to uncover data of 7 million customers: that's 0.2%

Doing low-hanging fruit isn't enough here. Honestly I just don't feel like the time is right to build such big DNA databases yet. Maybe one day with quantum encryption (can't observe the state without modifying it) or whatever else we may figure out, but today it just seems like you're taking a risk for yourself and half a dozen layers of relatives