View Single Post
Old 03-12-2025, 12:40 PM   #2661
jbjb
Somewhat clueless
jbjb ought to be getting tired of karma fortunes by now.jbjb ought to be getting tired of karma fortunes by now.jbjb ought to be getting tired of karma fortunes by now.jbjb ought to be getting tired of karma fortunes by now.jbjb ought to be getting tired of karma fortunes by now.jbjb ought to be getting tired of karma fortunes by now.jbjb ought to be getting tired of karma fortunes by now.jbjb ought to be getting tired of karma fortunes by now.jbjb ought to be getting tired of karma fortunes by now.jbjb ought to be getting tired of karma fortunes by now.jbjb ought to be getting tired of karma fortunes by now.
 
Posts: 772
Karma: 9999999
Join Date: Nov 2008
Location: UK
Device: Kindle Oasis
Quote:
Originally Posted by ratinox View Post
This is past to the edges of my expertise and experience so I'm not going to say yay or nay to the point (I have implemented hash-based auth but that was a very simplistic system for a POP3 client).
That's more expertise than most! Thanks for the interesting discussion. I hope I haven't come across as too pedantic - I've got a few decades of experience in related fields, and admit I have a tendency to get too picky (as my wife will confirm).

Quote:
But given that hardly a day goes by without another major breach being announced, it appears that doing things correctly is the exception, not the rule.
Nail meet head . By far the most significant issue is weakness in implementation.

Quote:
"If". Attacks always get better, and there are no takesies-backsies.
Agreed.
jbjb is offline   Reply With Quote