Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Facebook's is a little better - you can't disregard case entirely. Blizzard just cut the search space by a lot.

Then again, it would be pretty difficult to brute force a password in Battle.net, to be honest. I'm assuming they'd lock out the account after just a handful of tries.



> Then again, it would be pretty difficult to brute force a password in Battle.net, to be honest. I'm assuming they'd lock out the account after just a handful of tries.

Correct. ~5 failed attempts forces you to use your authenticator code, and if you don't have one, you need to use their reset form and a captcha.


The game clients will lock an account out after ~20 or 30 attempts and I assume the website will do the same. No one is going to brute force an account.


Yea, until someone steals their hashes.


But there are plenty of password stretching algorithms like bcrypt.

A very reduced keyspace, but we all knew people's password choices are poor anyway right?


Which is easier said than done. Honestly if someone can do that, you have bigger problems to worry about.


All your hashes are belong to us




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: