Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It could work... If you want to set minimal system requirements to visit your website.

It will also annoy users of password managers with auto-filling capabilities. "password" is normally used for actual passwords.

Besides, nothing stops the attacker from replacing your code with a faster implementation.



There are password hashing algorithms out there (like bcrypt) that specifically take a long time to compute using the fastest method that we can think of.


I shouldn't have named it "password". The idea was all the form fields are hidden and the process is transparent to the user.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: