Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It could work... If you want to set minimal system requirements to visit your website.

It will also annoy users of password managers with auto-filling capabilities. "password" is normally used for actual passwords.

Besides, nothing stops the attacker from replacing your code with a faster implementation.




There are password hashing algorithms out there (like bcrypt) that specifically take a long time to compute using the fastest method that we can think of.


I shouldn't have named it "password". The idea was all the form fields are hidden and the process is transparent to the user.




Consider applying for YC's Fall 2025 batch! Applications are open till Aug 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: