@seanmonstar Re:latest blog. I'm an attacker w/access; I will just quietly start inserting every hash until everyone can log in as everyone.
-
-
Replying to @jeremyrsmith
@jeremyrsmith his part 2 addresses that very attack http://www.opine.me/all-your-hashes-arent-belong-to-us/ …2 replies 0 retweets 0 likes -
Replying to @seanmonstar
@seanmonstar If an attacker has access to your DB, you already failed QED2 replies 0 retweets 0 likes
Replying to @jeremyrsmith
@jeremyrsmith I imagine the point was to be a defense against the public DB dumps we're seeing
2:37 PM - 10 Oct 2012
0 replies
0 retweets
0 likes
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.