Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Yes, it is. You should design your login system assuming that the username is public, of course (otherwise you would facilitate attacks targetet at a specific user), but for an attack on the site itself that needs just any one account, separate error messages reduce the complexity by several orders of magnitude.

Assume 8 characters out of A-Za-z0-9 for the username and 8 character out of 96 printable chars for the password. With a single error message, the search space is 62^8 times 96^8, with separate error messages it is 62^8+n times 96^8, with n being the number of users. This is far, far smaller if the number of users is noticably less then 62^8.

[edit: stupid comment parser ate math symbols]



This doesn't work very well if your password reset screen gives errors if the user doesn't exist. Or you can look up users by a given url. (deviantArt.com gives each user a subdomain that is the same as their username, easy lookup)




Consider applying for YC's Winter 2027 batch! Applications are open till November 2.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: