Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

A little scarey - type your precious passwords into our engine which records and transmits them to our server. For research! Really! We won't sell them, because we give them away. To researchers! Hackers totally won't ever see them, unless they pretend to be a researcher or something.

This will be a hard sell.



"This log does not contain the actual characters you type, but it does indicate whether each character was among those predicted by Telepathwords."

And, as always with password checkers, you can enter something similar to your actual password.


"we send the characters you have already typed to query our prediction engine" (under 'What information does Telepathwords collect and why?')


So they may actually be able to estimate what passwords are in use, by what people DONT type in? Interesting.


I really don't get the point of password estimators that need to send the password server side. I may as well just not have a password then.


Every time you log in to a site with a password, you are sending your password server-side. If you don't trust the recipient, don't send your password. But sending passwords to trusted servers is a normal part of using the web.


Normal to get some service you desire. But this site is just collecting them, by their own admission. Its a little strange to assume folks will trust them, because they ask us to. Consider what a hacker would say to fool people? How similar to this site's message would that be? Identical?


Not on blockchain.info is not.


In this case Microsoft say their prediction database is too large to load on the client, which sounds plausible. I certainly wouldn't put a real password in there though.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: