Hacker News new | past | comments | ask | show | jobs | submit login

No. The assertion is that it does fail to provide a benefit in practical, real-world cases, but defends against a fairly niche attack.

There's a reason that 'tptacek called it "security theater". Its implementors could better spend that time on actual security measures for things that are much more likely to happen...like defense in depth for credential leaking.




Consider applying for YC's Spring batch! Applications are open till Feb 11.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: