Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

They're verifiably hard to guess. That is fundamentally different.

(At least when passwords are generated with enough entropy.)



But does that make them different or are they just things that are easy to verify? If you could calculate the entropy of another authentication scheme would it be included?

The danger of security by obscurity is that your system might not have as much entropy as you initially estimate and can be easily defeated. Sounds a lot like the vulnerabilities in normal crypo applications, right?




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: