Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I use a unique password and even a burner email, and a phone number that I update every 8 weeks for my banking website.

It's taken blood, sweat and tears to save up 20k (a lot for me) and even though I have a secure authentication scheme for the website, I worry about it getting hacked all the time.

"...there is absolutely no risk"

You have no idea! There's little practical risk in people getting access to my (fictional) ProjectEuler account, but there is absolutely some risk into returning to the same scam twice. Say they exploit PE again and are able to extract more than just password and email, maybe they find a way to get more info about the user's browser, or cookies, or SOMETHING. Anybody foolish enough to continue to navigate to projecteuler.net will suffer the consequences. They'd be better off never returning.

I know the response to this will be, "Oh, you can't possibly expect people to just abandon services that are compromised once" but I absolutely don't expect people to do that. I do it, because my security is worth it to me. Others don't, and this is the sort of thing that happens.

We've no way to really isolate what happened to projecteuler, and no way to now what kind of nasty code got injected into the pages.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: