Hacker Newsnew | past | comments | ask | show | jobs | submit | more malcolmhere's commentslogin

This was the post that got to the front page:

https://www.reddit.com/r/InternetIsBeautiful/comments/4a4ol6...

The warmest feedback tended to come through PMs and email.


Thank you


Well spotted - I kind of mangled that explanation. The risk being mitigated is if somebody gets a dump of your old emails. Short-lived reset tokens don't help if they have full access to you email account.


Interesting site, never seen that before. It's kind of hard to get a feel for what the product does, though, without any screenshots.


Oh wow. Would love to know you did that. :-o


I feel like I’m posting a spoiler here, but... Think what happens if the user’s “e-mail address” happens to start with:

    "/><script>


Just put a script in the username field, sorry if that wasn't clear.

    <script>alert(0)</script>
All the live updating that module does, I figured there might be some code injection.


My bad, I've removed the reference to outdated password schemes. :-o


Give it a try, it's free! We don't cover mobile specifically, but if you are building APIs, much of the advise is useful. And thinks like password management are useful for every developer to know. :-)


Author here! I put this together because I was bit frustrated with the quality of teaching resources for my development team. (And I find the OWASP wiki a bit of a mess.)

Not sure about the business model yet, though it's peaked some interest here and on /r/programming, so I figure there's an appetite for good training material.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: