The difference is that neither the original nor mine actually submits the secret to the server. I went to great lengths to avoid actually doing it, it's still a bad idea to send a password to my page but at least you can check the source and network traffic and see that it's only checked with JavaScript and a hash is checked against the HIPB password site.
This supposed joke site sends and processes the key on their backend. At least it looks like that, I have not tried with a real key.
If this is just a meme website, just... take it back down? People are dumb, they are going to fill in real keys, and you knew this before you clicked "deploy".
> The maximum cycle length is 2256 ≈ 1.16×10^77 iterations. If you can evaluate 10^12 hashes per second, then working your way through all possible hashes would take you about 10^65 seconds (about one quindecillion times the age of the earth). Even if you're fortunate enough find a loop in a tiny fraction of that time, you're still liable to be waiting for trillions of years.
[+] [-] qualeed|8 months ago|reply
[+] [-] mdaniel|8 months ago|reply
[+] [-] gnyman|8 months ago|reply
These joke pages have been around since http://ismycreditcardstolen.com/
And I even made my own version https://hasmypasswordbeenstolen.net/
The difference is that neither the original nor mine actually submits the secret to the server. I went to great lengths to avoid actually doing it, it's still a bad idea to send a password to my page but at least you can check the source and network traffic and see that it's only checked with JavaScript and a hash is checked against the HIPB password site.
This supposed joke site sends and processes the key on their backend. At least it looks like that, I have not tried with a real key.
[+] [-] Arcuru|8 months ago|reply
[1]: https://faxyourballs.com
[+] [-] ivanjermakov|8 months ago|reply
Exactly what a phishing website would say.
[+] [-] yieldcrv|8 months ago|reply
[+] [-] BenjiWiebe|8 months ago|reply
[+] [-] StefanBatory|8 months ago|reply
[+] [-] DonHopkins|8 months ago|reply
[+] [-] ignoramous|8 months ago|reply
If this service was serious, it'd instead rely on fingerprints (sha256/sha512) and not the key itself.
[+] [-] mr_toad|8 months ago|reply
[+] [-] goopypoop|8 months ago|reply
[+] [-] gblargg|8 months ago|reply
Oh, OK.
[+] [-] mightysashiman|8 months ago|reply
[+] [-] thasso|8 months ago|reply
[+] [-] isoprophlex|8 months ago|reply
[+] [-] nativeit|8 months ago|reply
[+] [-] smidgeon|8 months ago|reply
[+] [-] alberth|8 months ago|reply
[+] [-] ghusto|8 months ago|reply
[+] [-] TheRealPomax|8 months ago|reply
[+] [-] gblargg|8 months ago|reply
They are now!
[+] [-] nailer|8 months ago|reply
[+] [-] joemazerino|8 months ago|reply
[+] [-] cryptonym|8 months ago|reply
[+] [-] DonHopkins|8 months ago|reply
https://wordpress.com/plugins/browse/counter
[+] [-] kekebo|8 months ago|reply
[+] [-] nullc|8 months ago|reply
[+] [-] knowitnone|8 months ago|reply
[+] [-] nativeit|8 months ago|reply
https://stackoverflow.com/a/43636715
Edit: fixed missing exponent notation
[+] [-] actinium226|8 months ago|reply
[+] [-] daft_pink|8 months ago|reply
[+] [-] comrade1234|8 months ago|reply