Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Right, but by typing a few characters I can establish if a user has an account or not, for a subsequent attack.

http://news.ycombinator.com/item?id=3059759 (top comment thread)

http://news.ycombinator.com/item?id=3156841



But how is that different from Googling "site:bagcheck.com John Smith"?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: