Skip to content

Comment on One-time Secret: Share passwords etc with URIs that work only onceparent

Comments

Agree. I know it says that you can't do anything with the data, since necessary information isn't available. But... even if its random, it is known that it is a password. So, it's feasible to build a table of known passwords, at least.

How would that work? The URL only works once, so even if they crawled every possibility, the intended recipient would never get it, and would alert the sender.

I'm just theorizing. But let's say the site gets compromised for a few days/weeks and they don't find out.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.