Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Think on that statement for a moment. If you wanted a particular set of colors for your password, and then you could turn around and actually come up with that password... see the problem? Hint: 'non-reversible'.

This idea, in its current form, sucks. It's not as bad as what you're suggesting, but it comes close - as has been pointed out by many others, if you can watch the colors change with each keystroke, you can pretty much trivially recover the password.

And it's just unnecessary. Password typos are not some huge problem begging for a solution. If you need quick confirmation of matching passwords, just compare the two fields directly, raise a warning icon if they don't match and a checkmark if they do, and be done with it. You'll even save your users a few brain cycles comparing colors.



Second thought- this is an awful idea. I didn't think of it in that way, and it does indeed seem like a security risk. Your password might as well be the three colors.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: