To the people who are worried about giving up their password, who cares if he gets them? Are passwords really even that worthwhile without being able to tie them to some account on some site?
Let's say that one of my passwords is n0TMyR34lP4sSw0rD, and I enter that into the site. So what? Now you have to guess my username on a site that I might have an account on. Not to mention weeding through all the garbage from people entering in random passwords just to see what the results are.
I understand that being proactive about security is a good thing, but I really think the potential of this being successfully used maliciously is fairly non-existent.
They could create a database with hashes of these passwords and compare them with the recently leaked Gawker hashes. Not all of those passwords have been cracked yet, especially the more complex ones.
Comments
To the people who are worried about giving up their password, who cares if he gets them? Are passwords really even that worthwhile without being able to tie them to some account on some site?
Let's say that one of my passwords is n0TMyR34lP4sSw0rD, and I enter that into the site. So what? Now you have to guess my username on a site that I might have an account on. Not to mention weeding through all the garbage from people entering in random passwords just to see what the results are.
I understand that being proactive about security is a good thing, but I really think the potential of this being successfully used maliciously is fairly non-existent.
They could create a database with hashes of these passwords and compare them with the recently leaked Gawker hashes. Not all of those passwords have been cracked yet, especially the more complex ones.