Ask HN: Need your input on an idea in the realm of Web security Hello HN, I have an idea. What do you think about the concept and do you think that there's an opportunity there? Problem: One of the most fundamental problems in Web security is password reuse, right? For all the communication campaigns and all the alerts that companies send to their users, most users just don't care enough not to reuse their password across websites. And most companies do not dare to force their users to change their passwords regularly. At the same time, these very same companies are the ones getting the backlash when user accounts suddenly get compromised en masse. Goal: What if we had two 'simple' ways of improving security for many users across many websites? 1. What if a website could find out, when a user signs up, whether there already exists an identical login/pass "somewhere" on the Internet? Then it could say "eh, how about you chose another password? 2. What if a website could find out whether the guy trying to sign in has attempted to log in dozens of other websites in the past hour, logins that were unsuccessful? Then it might be that an attack is going on and the company could freeze the account and alert their user. More information in my comment below (sorry, I kept exceeding the 2.000 character limit) |