How could GitHub improve the password security of its users?
20th November 2013
My answer to How could GitHub improve the password security of its users? on Quora
By doing exactly what they’re doing already: adding more sophisticated rate limiting, and preventing users from using common weak passwords.
Their account security practices are already best-in-industry: they support two-factor authentication and their “Security History” interface at https://github.com/settings/secu... is the best I’ve seen on any website.
The way they store passwords (correctly, using bcrypt) had nothing to do with this particular security incident.
More recent articles
- Notes from Bing Chat—Our First Encounter With Manipulative AI - 19th November 2024
- Project: Civic Band - scraping and searching PDF meeting minutes from hundreds of municipalities - 16th November 2024
- Qwen2.5-Coder-32B is an LLM that can code well that runs on my Mac - 12th November 2024