335 karma · joined April 6, 2012
[ my public key: https://keybase.io/robmil; my proof: https://keybase.io/robmil/sigs/x_AOtOjtMev0kghH-FH4D5BvfrDlPtKBKlRF83jdcxs ]
It's no less secure than a password reset and would mean that legitimate account owners can't be locked out of their accounts by attackers.
Not too inconvenient for legitimate users trying to remember their passwords, but it surely makes bruteforcing impossible (if by the 1,000th attempt they're having to wait an hour between attempts).
Even ancient civilisations kept orders of magnitude more records than have survived now, and they even had the added bonus of being physical — with linguistics the only obstacle to future generations' reading of their content. Our mass of data that seems so permanent is wrapped up in proprietary file formats; it's stored on volatile media; and it's kept around by companies who, in the context of centuries, are flashes in the pan.
How much of the digital information you possessed even ten years ago is still readily accessible? I know in my case there's not a great deal. Now extrapolate that forward 50, 100, 150 years…
If you have a large number of inactive users, this might not be as effective (you'll still be left with lots of MD5 hashes in the event of a dump) but for other sites it can be quite useful.
You can also use the same strategy to increase the work rate of your bcrypt hashes in the future.
It's interesting how, long after one is aware of the complete randomness of output like this, one's monkey brain is still prepared — against all rationality — to read profundity into gibberish.
About the strongest endorsement I can give is that it makes me wish more of my logs were in JSON format, rather than wishing that less were as I always had before.
I find it more annoying than the lack of, say, Cmd + T in MacVim, so I've found myself spending more and more time using that — even after a concerted effort to use SublimeText for a while.
It's a generally interesting point though, that feeds into questions of what the general purpose of SSL is. This still has benefits for the end user — the café owner/hotel company/etc. can't modify their connection — and so surely is better than nothing, but is it enough?
You can work to whatever actually hooks you want (onscroll, onhover, etc.), and then just call Socialite to actually replace the links.