Project Euler Returns
projecteuler.net
projecteuler.net
However, not storing emails, and thereby giving up account recovery with the explanation that it's about security is a shit sandwich.
My email is <myfirstname>.<mylastname>@gmail.com, a pattern I share with millions of people. This is public information. I could spray paint my email address on local bridges without in any way making my email less secure (cops might complain, though).
I understand that some people have reasons to have private email addresses that they don't want released (they'll give them to family, but not the general public). They should never sign up for anything with those email addresses, because the moment you sign up for things, you will almost certainly be entered in a database somewhere, and eventually be spammed or subjected to whatever other bad consequences you're concerned about.
Account recovery is a basic feature of a website (except those that contain data too sensitive to have account recovery), and they're giving it up for phantom security.
Not having any personally identifying information doesn't protect your Project Euler account, it protects your other assets.
Because while an email and a password is not public information, a username and a password isn't public information either. If you don't trust yourself to store the former, you shouldn't trust yourself to store the later much either.
So, the same general class of people who you endanger by not storing email/password securely are endangered if you stop storying email and just have username/password.
And a lot of that class will have emails that can be quickly guessed by appending one of "outlook.com", "gmail.com" or some other popular free-webmail provider to the username, because if they reuse usernames and passwords, its quite likely they do it on their mail site and that they have a webmail provider. So while what Euler has done clearly has a significant convenience impact, it has negligible security impact.
How do you propose to look up accounts by email address if they use a salted hash? You would have to bcrypt the email against every row in the database until you found the correct one. If you use a username to do the lookup instead, why store the email address at all? You can't use it for anything.
Wrong, because it's the logical conclusion of the belief that emails must be treated with as much care as passwords. If you really think that, then you need to encrypt them, and therefore you have to give up the ability to look up user accounts by email address. All you could do is verify that a user-submitted email is associated with a user-submitted account. That's where you end up when you have that sort of paranoia about email addresses.
But that conclusion is, like you said, absurd, and I never should've implied otherwise. I wasn't thinking when I wrote it.
A site that purports to teach is incapable of learning of how to strike a balance between securing confidential information and making it possible to recover an account. This is a solved problem. If my bank can have a password recovery system, a site about numbers can have one too.
> " With respect to this issue it is quite possible that some members will have genuinely forgotten passwords."
Who hasn't "genuinely" lost a password?
I would think in this case the entire point is not so much to help them secure stuff, but an attempt to remove them as a target for hacking in the first place.
This is very short sighted. As long as you have a popular site you're a target for defacement. And the convenience expense is enormous. As others have mentioned oauth or a twitter or facebook login alternative would have been a sane choice, what they've decided wasn't sane, it's embarrassing for them and frustrating for users who trusted the site.
Inconveniencing users to this degree is probably causing the hackers to laugh, this is in effect a huge win for them they can go brag about now in addition to accessing sensitive information.
(I did, cannot recall that password so far and it's not in lastpass for some reason - maybe too long ago/before I got into that habit)
1) had solved a bunch of Project Euler problems, but fewer than 200 (account recovery is still available for those folks), 2) lost/forgot your signon information, and 3) lost/deleted all the code you used to find the answers?
You, sir, are in a very small boat. A frustrating boat, to be sure, but I suspect that virtually none of their users share your fate.
OK, so it's an extremely minor issue, but given that the reason for it is so silly, it's still kinda irritating.
I suppose they could charge 1 USD for (lifetime) membership and store the last four digits of your credit card in lieu of a username, so that they could easily look up the salt that gives the salt with witch they've hashed your email... ;-)
(Would require that you could supply the last digits of your possibly expired credit card, when you lost the password ten years hence ...)
Check the the email provided by user via the recovery form against a hash of the email saved during registration, if it matches send the reset link. This way when data is breached, figuring out what the original email should be hard (if not impossibly hard, depending on how they hash it).
Am I missing something here?
Apart from that, I don't see any issues with that approach. Not sure why project euler doesn't use that approach.
I agree with someone up there that email address != password. It's refreshing to see someone that gives a crap about my privacy though.
Still, simply storing the create time or a randomly generated salt right on the user table is more secure than using a global salt.
If your hashing algorithm is appropriately "expensive" the scan all user salts would not work.
Personally I think not having a password retrieval function while simultaneously forcing all of your users to reset their password is a pretty user unfriendly tactic for the protection of an ostensibly public piece of information.
Sure having another field to match on (eg: username) for locating the correct salt would be good -- but it's certainly not infeasible to do a brute force search (probably want to queue up password request requests, though). Now, if you went with bcrypt or scrypt -- things would, by design, break down a bit. I still think you'd be able to send a reset mail within 24 hours for most reasonable configurations and number of users...
Even worse, an invalid email would take the longest possible time, every time.
And since this is only an email address we are talking about, a global salt + more stretching (like runamok mentioned above) could be secure enough while still providing faster lookups.
> figuring out what the original email should be hard (if not impossibly hard, depending on how they hash it)
I mean, passwords are way more sensitive than emails, especially given that many people re-use them. So, how you hash passwords is more critical than how you hash emails (which is rarely done, I guess).
On the other hand, there is no reason to not have the same level of protection for emails, if you are already following best practices for passwords anyway (PBKDF2, bcrypt, scrypt etc.).
(And "hash" is a bit misleading: http://codahale.com/how-to-safely-store-a-password/).
Oh, you've lost the game long before that. Grandma's email chain? Welcome to the database as soon as anyone on that list gets their email compromised. Apologies to all the grandmothers out there who know how to use the BCC field.
Must have been really tempting to just sack it off as a bad job. Congrats to the team!
I know OAuth has it's own warts, but isn't part of the point to offload the burden of authentication to someone else?
Also, feel free to replace OAuth with Mozilla Persona or OpenID.
[edit] - s/storing less password/storing less information\(email\)/
I've been keeping this idea close to the chest, mostly because it's something I want to do, but Project Euler could easily become a great training tool, an easy-to-install packaged django application(I mention django for it's nice out-of-the-box admin interfaces, doesn't matter what it is as long as it's easy to manage for admins and users)
I love PE and I don't intend this question snarkily at all, but am genuinely curious why securing a database of emails for a site as simple as PE would be such a perilous problem? I know security in general is always more difficult that it appears, but in this case I would have thought we were dealing with a solved problem. I'd love to hear about why my assumptions are wrong.
Security is not just intrusion prevention, it's also detection and recovery. PE chose to reduce the negative effects of a successful intrusion.
Ergo, I find it quite plausible that people who are doing this in their spare time chose to avoid this task.
Not storing personal information now removes a whole class of work you have to do. While you store personal information, you need to spend time keeping on top of security patches and issues. It means you need to worry about legal obligations.
If you just don't store it, you don't have to worry about that. You need to spend less time per month maintaining the project. If you're a volunteer project, you might not have the time available to keep on top of it.
What is in the opinion of the HN community a good score on Project Euler?
For which scores do you tip your figurative hat?
The first 50 should be doable for most people in my opinion. After that you need to start being really clever or actually going and researching the problem at hand.
There are certain "developers" who can't even fizz buzz their way out of a paper bag.
At some point the math was beyond my knowledge, and I didn't find much fun in researching it.
I'm a fairly normal web developer, in my own estimation.
Keep doing the problems until you get stuck. Then learn, then solve a few more. Repeat as long as you're happy with your progress. I wouldn't put a number on it.
In fact, do some easy ones in a completely new language!
If I work on it for a week, get frustrated, google for solutions, and can't find any, and you solved it, you're a beast.
Also if you solve 328 tell me how. And no, dynamic programming is not efficient enough.
Is your dynamic programming table 2D? Maybe it should be.
Stop reading if that's progress.
Have you looked closely at the table content?
Stop reading.
Have you noticed how similar many parts are, under perhaps simple transforms?
Stop reading.
Try adding or subtracting your coordinates, to see more of the pattern.
Stop reading.
There's not just a within-row pattern.
Stop reading.
In the end, dynamic programming might not be the main trick. But you can make your own way from here.
Neither the news page, nor the "about" page, nor the front page of "Project Euler" care to explain what this website is all about. Of course, I can guess that it has to do with mathematical problems of some sort.
It is sad if you have to turn to Wikipedia to find out the basic details about a website. A sentence or two of introduction would have made everything better :-)
http://en.wikipedia.org/wiki/Project_Euler
""" Project Euler (named after Leonhard Euler) is a website dedicated to a series of computational problems intended to be solved with computer programs.... Problems are of varying difficulty but each is solvable in less than a minute using an efficient algorithm on a modestly powered computer. A forum specific to each question may be viewed after the user has correctly answered the given question. """
There are also several Github repos out there that have both the problems and hashes of the answers. (Some have the actual answers, as well, or used to in the git history, but presumably anyone interested in solving the problems is more interested in the process than the score.)
Remember kids: Most software development isn't about puzzle solving and algorithms, it's about making stuff like forms work properly.
Of course the puzzles and algorithms are fun, which is why I'm signing up for PE again!
But that doesn't really address a question about putting together an open-source one.
There's also at least one similar-to-Euler one -- rosalind.info (like Euler, but bioinformatics focus) -- which might be closer to responsive, since even though its not open source, their FAQ says they intend to open-source it...
It's a lot of fun; the math involved can get pretty advanced on some of the problems.