Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I mentioned exactly those what I think "some way to narrow it down" is, mainly new websites with significantly less users, websites where its common to have your username known in public, and even websites that allow you to query their APIs for username data.


I guess I don't see how that would matter if the website were new. You still would have to obtain a username list prior to new users signing up (assuming they use the same password as the one you're trying) and even then you're also assuming the website doesn't detect the intrusion and advise users to change their passwords.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: