theartisan changed the topic of #rubygems-trust to: Current Status: drafting requirements. please leave comments on http://goo.gl/ybFIO :: Logs at http://irclog.whitequark.org/rubygems-trust
<theartisan> Mine asks for individual letters of a password, so the pass is obviously plaintext... then 2-factor for transactions
<tarcieri> I like banks that make you pick a special passphrase they display to you
<tarcieri> and a special "security image"
<tarcieri> because there's no way to MitM that shit
<tarcieri> lol
<namelessjon> theartisan: They could have a dozen bcrypt'd fields. Not that it matters with a password space of 26 or 36 ;)
<namelessjon> Hmmm. Actually, could you do something with shamir's secret sharing, so that you did actually have to know all three/n letters together? (but even that wouldn't be a large password space)
<theartisan> Yeah, they tell me to protect my pin, but store it plain text in a database, leading by example...
<theartisan> Or as close to pain text...
<namelessjon> You hope in some kind of HSM for a bank. But only hope :/
billdingo is now known as billdingo-afk
<tarcieri> lol
<namelessjon> A secret sharing approach could make it 36^3, instead of 3*36, which is a factor of >100 harder, but its 100x a really tiny number.
<namelessjon> I'm off, though
<tarcieri> ttyl namelessjon
qmx|away is now known as qmx
qmx is now known as qmx|away
_whitelogger has joined #rubygems-trust
davidbalbert is now known as davidbalber|away
havenwood has joined #rubygems-trust
havenwood has quit [Remote host closed the connection]
havenwood has joined #rubygems-trust
havenwood has quit [Remote host closed the connection]
havenwood has joined #rubygems-trust
havenwood has quit [Remote host closed the connection]
theartisan has quit [Ping timeout: 252 seconds]
workmad3 has joined #rubygems-trust
workmad3 has quit [Ping timeout: 252 seconds]
theartisan has joined #rubygems-trust
workmad3 has joined #rubygems-trust
billdingo-afk is now known as billdingo
workmad3 has quit [Ping timeout: 245 seconds]
workmad3 has joined #rubygems-trust
qmx|away is now known as qmx
davidbalber|away is now known as davidbalbert
davidbalbert is now known as davidbalber|away
davidbalber|away is now known as davidbalbert
pencil has quit [Ping timeout: 245 seconds]
qmx is now known as qmx|lunch
havenwood has joined #rubygems-trust
billdingo is now known as billdingo-afk
qmx|lunch is now known as qmx
workmad3 has quit [Ping timeout: 272 seconds]
davidbalbert is now known as davidbalber|away
davidbalber|away is now known as davidbalbert
davidbalbert is now known as davidbalber|away
davidbalber|away is now known as davidbalbert
havenwood has quit [Remote host closed the connection]
workmad3 has joined #rubygems-trust
workmad3 has quit [Ping timeout: 245 seconds]
qmx is now known as qmx|coffee
davidbalbert is now known as davidbalber|away
qmx|coffee is now known as qmx
havenwood has joined #rubygems-trust
davidbalber|away is now known as davidbalbert
workmad3 has joined #rubygems-trust
davidbalbert is now known as davidbalber|away
qmx is now known as qmx|away
workmad3 has quit [Ping timeout: 256 seconds]