Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The PIN for the hardware passkey device in my locked drawer at home is 1234567.

Oh no, you have its PIN! Can you now log in to $service as me?

Not without that hardware module.

My password for $service is hunter42.

Now you can log in as me.

See the difference?



I am trying to come up with a counter argument but gave up. Since you are correct.

Is it fine if a waive my hands around and say "complexity"?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: