Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

doesn't change the vector of this attack one bit: weak password


Weak password wasn't the vector. Weak password reset feature was.


Yes it does change that vector. I'm talking about the physical tokens which generate a new key every 30 seconds, like:

http://www.rsa.com/node.aspx?id=1156

This way you need to know the password _and_ have the physical token in your hand to know the current key. On the downside, it's also a hassle to carry it around and use it (I have a couple of 'em for access to various supercomputers), so I wouldn't bother doing it for my own email, but if you're a public figure or otherwise sufficiently paranoid it might be worthwhile.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: