Show HN: LeapFM - A new way to find music
leapfm.com
leapfm.com
Needs on-screen genre tags, also needs submitter ID so you can spot people whose taste you know you like. Otherwise clicking on an unknown artists is a complete crapshoot.
As a site owner I'd like to be able to look people (or a judge) in the eye and say "I followed realistic best practices in protecting your password - I put technical measures in place to ensure the password storage wasn't so weak they could be expected to fall in under an hour to a curious journalist running HashCat on has laptop as part of a story he's writing."
(Story time: I once signed up for this interesting sounding new website/service "just to see what it was". I used my usual "throw away" password. The same email and password I'd signed up to PerlMonks with. Several years later, that new website had become a regular part of my online work and social life, and a place where I cared about my reputation. I hadn't - back then - had a process in place to remind myself where I was using weak or reused passwords, so when the PerlMonks site got hacked (with their plain-text password storage!), all of a sudden my friends/colleagues/clients started getting Acai Berry Spam from my Twitter account…)
However, the real value of salting a hashed password is in defeating multiple password cracks. The salt is like a nonce added to a each individual password so that if you crack one, you can't formulaically crack them all. While en masse this is tedious, applied to a single password it's meaningless because the processing time for brute-forcing a salted hash and a non-salted hash will be trivial. It's mainly useful because you can't "recycle" computational power applied to one cracked password for another, assuming you have e.g. a database in front of you.
To give a quick explanation of why a salt won't protect a single password, consider it this way - salting passwords allows each hash to come out differently, such that if you try to crack a list of passwords using a single algorithm it won't work because the salt randomizes each one. Repeating the computational steps for cracking one password will be null and void for finding additional passwords if they're salted - you'll have to start over.
There just aren't enough words in most people's vocabulary for a "dictionary word" to provide enough bits.
Salts help, but HashCat on a decent GPU will test over 2million password/sec for salted MD5 hashes using phpass (the current WordPress password storage). That'll rip through the whole RockYou password list (32m words) in 15 seconds. Anecdotal evidence suggests something like 25% of typical passwords from publicly available dumped hashes fall to the RockYou list. Salts mean I ned to run each hash individually, but a 25% chance of revealing each hash's password in ~15secs isn't much of a challenge.
(Oh, and the "journalist with a laptop" comment was about this: http://arstechnica.com/security/2013/03/how-i-became-a-passw... not a bad read if you're curious. See page 3, almost 5000 passwords out of a list of 17000 unsalted MD5 hashes in _one_ minute - on a laptop without using a GPU…)
That said, I signed up anyway and hope the service does well. I just think this is an ideal candidate for OAuth or some other low-friction thing, because it's supposed to be fun and enjoyable - and I'm a musician, so I'm more professionally interested than most users would be.
(Oh, and on the "I'll switch it later" comment – do you have a plan in place to enforce that? For a while I'd register throwaway accounts with a universal-low-grade-reused password, then search for that password every month in 1Password and decide to change/keep the password, or to delete the login. But it's less effort to just let 1Password generate good passwords when I register rather than deal with bad passwords on a recurring monthly basis... (And now I just get to rant about sites that won't accept random 25 char upper/lower/digit/symbol passwords…))
Wonder who the marketing mentor/teacher is.
With reddit-style voting and embedded youtube/uploaded mp3 tracks.
In fact, I would rather go to youtube and sort by videos by popular instead. They have bigger user base; users are more actively participating in voting, etc...