All tokens/passwords are now encrypted on Sparklabs!

That means that I had to wipe the DB, so please remake your account!

As before, first 10 people to join get verified!

Sorry about the static links for now, I need to learn my templating engine to make it better.

https://sparklabs.amorogos.repl.co/static/join.html

https://sparklabs.amorogos.repl.co/static/login.html

Oct 18, 2022, 5:20 PM
3 1 45

comments

Please don’t just encrypt your db, it does not guarantee security, good access control is better than just having it public and encrypted. Please use something like MongoDB Atlas (free 512MB cluster, no payment details required) or use some other sort of database on a self hosted server.

also, isn’t sha256 actually very insecure

idk, i need to salt them

You need to use a more secure algorithm like bcrypt, scrypt, or argon2

after I make some other stuff

sha256 is very insecure for passwords because it is way too fast, it can be brute forced pretty easily

oh, okay. I didn’t know that. Now I know, and knowing is half the battle.

nah, gonna use the server my dad owns

lucky ahh mf

20GB VPS in Seattle

Your website has no home page.

yeah, I know. are you @lurn?

no that’s not lurn

lurn is just called lurn, they have a wasteof i think but i forget it

is it the twitch streamer :thinking:

See more replies

and also who made their username ni**a

i haven’t made any accounts, also add a username filter and ratelimit

okay, I will do those things.

it is now rate limited 2/ second from join/login

I'm not lurn

please don’t encrypt passwords. passwords should be hashed (irreversible) rather than encrypted (reversible).

oh, sorry for not explaining. the passwords are hashed, then encrypted.

I encrypt them because all the data is public on replit and don’t want people bruteforcing them.

but… why is it public on replit?

because I am too broke to

  1. buy replit hacker

  2. use my dads server

  3. or buy my own vps

in other words, I don’t have much money.

I actually have $24 USD but still, I need more money and an actual website before my dad would host it for me.

If you’re a student you can try applying for GH edu pack, gives you $100 per year in Azure credit, which you can get a b1s instance for that. Also Replit hacker plan is not recommended either, self host or host in a proper VPS.

gonna use my dads server

I joined, pls verify!

done. please verify again!!!!1!!1!!11!11!!