Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

a bugmenot type service...except it would act as a proxy. The proxy will be used to hide the actual login info, and to prevent the users from screwing around with the actual account.(basically I see this as changing the username to XXXX, not letting users go to pages like usercp.php etc).

Right now bugmenot is pretty much useless, since all accounts are dead almost right away.

This way the passwords etc will remain private, and the accounts won't go dead right away



I assume the accounts go dead mostly because the content providers kill them, not because individual users kill them. There isn't much you can do to stop a content provider from figuring out which accounts are bugmenot accounts and killing them... It's an arms race to see who will give up first.


more reason to keep the login info secret. Sure they can figure out the account by multiple ips...but that takes a little bit more effort.

Honestly, I think the user side portion is a bigger problem. Its all the psychology, people change the login info so that noone else would be able to do the same thing and prevent their access.


In addition to Jerf's comment, I will also point out that you can't hide the login info from the content providers. All they have to do is steganographically encode the user name into the web page content. Then they can use your bugmenot-like service to retrieve the page, extract the user name, and cancel the account.

I still see no benefit to the users changing the account info. This is to access sites with free accounts, yes? In that case, isn't it actually just as much work to assert control over multiple bugmenot accounts as it is to sign up for the free accounts in the first place?


You can not hide login info from the people you are logging into. All they have to do is install your plugin and start logging in. Whatever clever algorithm you put in place to expire canceled accounts works in their favor too. Less than a day's worth of scripting and I can fully automate this within Firefox.

I'll say it again: Whatever counter claim you think you have, you can not hide login info from the people you are logging into.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: