HNHacker News
TopNewBestAskShowJobs

chunsaker

276 karma · joined May 22, 2010

I run marketing and BD at Stormpath. Github, Twitter, Linkedin: all @chunsaker.
submissionscomments
chunsaker··on Password Breach? That'll Be $172,000,000 Please
Sure, but designing around the inherent riskiness of user behavior/forgetfulness is an important part of security systems. Users want to be protected, not for blame to be shifted to them.
chunsaker··on Password Breach? That'll Be $172,000,000 Please
What happens if your phone gets stolen?
chunsaker··on Introducing MongoClient
Yay for error reporting - glad to see the Mongo community got heard on this one.
chunsaker··on Electronic demon costume is surprisingly unnerving
Not unnerving, but pretty awesome!
chunsaker··on Do you want to be programming at 50?
One reason to stay coding - even if you're not on the cutting edge - so you can teach your kids, or even grandkids. My dad was 40 or 41 when he gave me "BASIC for Kids" - I moved on to html and java, and if he had made it to 50, it would have been super fun to hack through a weekend with him. I hope I can do that with my daughters and granddaughters!
chunsaker··on Password Security The Right Way
Totally Agree! I wanted to keep the scope for this narrow so it didn't turn into a total beast. The guys over at Cloud Passage have some great content on server security (http://blog.cloudpassage.com/) that I think is really well informed, and we're going to do a followup on backend security.
chunsaker··on Password Security The Right Way
You're talking about Bcrypt like its some magical golden unicorn that will cover your ass from all attack vectors. Sure, its awesome. But modern security requires more than just an awesome encryption algorithm.
chunsaker··on Password Security The Right Way
Totally agree Coda gets the basics right and I love that article. In fact, our CTO wrote a response blog article to that in February: http://www.stormpath.com/blog/strong-password-hashing-apache...

However, to quote from that post: "The author is correct assuming the attacker has direct access to your password store. This is a big assumption - most organizations go through great lengths to ensure access to say, databases, is levels of security 'deep' beyond just a web login form. Anyway, assuming that this might ever happen to you, how can you address the issue?"

← PreviousPage 2 of 2