Hacker News new | past | comments | ask | show | jobs | submit login

There is a difference between this kind of password and the password for a server.

With the OP system the attacker gets potentially way more attempts to access the page and gets to try in the future with whatever tech comes out. On the plus side it is E2E encrypted!

With a traditional server they can rate limit attempts on the password. But they probably don’t encrypt it using YOUR password (unless it is a password manager etc.) so an attacker could get the plaintext if there is a breach.




Consider applying for YC's Spring batch! Applications are open till Feb 11.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: