Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Well, I watched network connections and saw none. Do that + use Incognito mode = you're probably good.


He recently changed it to use a random seed sent from the server instead of the client-side RNG. Over, I believe, unencrypted HTTP. Your suggested countermeasure would not have detected that attack; indeed, perhaps it was already in place before you reported no evidence of attacks.

It would, however, have made it harder for him (or your ISP) to tell whose password they'd stolen.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: