Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I’m not sure what the point really is, they pay pennies to people in Bali to sit around and solve these. Anyone who really wants to get in is going to get in. At best it keeps honest people honest.

Check out this guy on YouTube, he can pretty much open any lock in thirty seconds without causing any physical damage, will change your whole perspective on security.

https://youtube.com/c/lockpickinglawyer

It’s better to plan for people getting in then depend on preventing it.



The point is to raise the price of the attack.

If someone wants to make 10,000 accounts, I'd rather it cost them 5 cents per captcha solve, $500, than for it to be free.

Some attackers can make it pay off, but many can't, so they don't try. That makes my life easier, as I'm the one being paged during an attack.


But that's why this proof of work scheme doesn't make sense.

I assume attacker doesn't need the accounts immediately. I also assume that a real user will wait at most 10 seconds when creating an account on their old underpowered phone.

So the attacker could either wait 27 hours (10*10000 seconds) to do the attack, which for most attacks wont matter much. Or they could use some high powered aws instance that's 100x as powerful as the phone and wait a few mins (aws pricing aint that bad if you just need 5 min of compute time).

Yes it increases "costs" but not by very much and not in a way that scales




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: