How could GitHub improve the password security of its users?
20th November 2013
My answer to How could GitHub improve the password security of its users? on Quora
By doing exactly what they’re doing already: adding more sophisticated rate limiting, and preventing users from using common weak passwords.
Their account security practices are already best-in-industry: they support two-factor authentication and their “Security History” interface at https://github.com/settings/secu... is the best I’ve seen on any website.
The way they store passwords (correctly, using bcrypt) had nothing to do with this particular security incident.
More recent articles
- Tips on prompting ChatGPT for UK technology secretary Peter Kyle - 3rd June 2025
- How often do LLMs snitch? Recreating Theo's SnitchBench with LLM - 31st May 2025
- Talking AI and jobs with Natasha Zouves for News Nation - 30th May 2025