Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Two factor limits the time window within which a password is useful. If one of your complex password's hashes gets exposed, someone would need to also know your ssl-only two factor auth cookie, and then reverse/bruteforce your password within the 30 day window the cookie makes it valid for - that makes the "current model" of releasing the hashes on pastebin and crowdsourcing the hash-cracking much more time critical.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: