HNHacker News
TopNewBestAskShowJobs

markhemmings

659 karma · joined August 14, 2012

[ my public key: https://keybase.io/mhemmings; my proof: https://keybase.io/mhemmings/sigs/7BkhXPNWmr2KA4bxYjmostAaSiXjb-BNLdia_yaZ5ZY ]
submissionscomments
markhemmings··on Emoji One
Epic how quickly that XSS vulnerability was fixed. Great work guys!
markhemmings··on UK government's password checker sends plaintext password in the URL over HTTP
My initial thoughts are just why not do this client side using javascript? No need for the string to leave the client.
markhemmings··on WordPass – Hate passwords, love passphrases
I agree with and applaud the use of seriously here ;)
markhemmings··on WordPass – Hate passwords, love passphrases
True, account should be disabled after x number of bad guesses. But securing against a "brute force" attack for me is more a case of cracking hashes from a db dump. It's easy to churn though vast numbers of hashes in no time at all these days. Here things like hashing algorithm speed, number of iterations, unique salting and original password length all have a part to play.
markhemmings··on WordPass – Hate passwords, love passphrases
Completely agree. For example, I use two-factor authentication on all accounts that allow me to. Regarding limiting to 12 characters, the sites in question there are putting there users at risk and it's very likely they aren't storing passwords correctly, leaving anything you put in that password box vulnerable anyway.
markhemmings··on WordPass – Hate passwords, love passphrases
It was a larger number at first, but try remembering say 10 words in a row over a long period of time; most people find that difficult. If hashing is implemented properly (i.e. is slow with a large number of iterations) then passphrases shouldn't have to be that long. And if it isn't, then pretty much anything you use will be as bad as each other (Some people are still using MD5 for example!!) :)
markhemmings··on Huge Spam Attack Trending on Twitter ("How to lose 20lbs")
"How To Lose 20lbs" is currently trending on Twitter. Vast numbers of profiles seem to be tweeting the spam link
markhemmings··on How to implement HTTPS in an insufficient manner
I'm the guy who originally contacted Troy Hunt about this, as he mentions in the blog post.

What annoys me is I'm a very young developer, and I've only really just become interested in security (12 months ago I didn't even know what hashing was!!!), yet there's developers out there with years and years of experience making huge sites for the likes of Tesco and TopCashBack for vast sums of money and they don't think about incorporating even the simplest foundations of internet security a novice like me would implement without even thinking! How is this possible?! If I'm doing it in tiny little php sites with 1 unique visitor ever, why are these 'experts' not in there huge corporate sites with hundreds of thousands of users a month?!

markhemmings··on The feature supported in IE6, but not Chrome
Good question. Why doesn't chrome decompress it when their header suggests they will? Yes it's unneeded and discouraged, but if developers do send gzipped content such as images (which as we all (including the blogger) know, they definitely shouldn't!) surely chrome should just go ahead and decompress it as normal?