300M Freely Downloadable Pwned Passwords
troyhunt.com
300M Freely Downloadable Pwned Passwords
1–10 of 184 posts
Re: 300M Freely Downloadable Pwned Passwords
#2Troy mentions some arguments against torrents, but it is better to have a authoritative torrent than none, imo.
Re: 300M Freely Downloadable Pwned Passwords
#3Who do we lobby to get them to fail their next PCI-DSS compliance test?
Re: 300M Freely Downloadable Pwned Passwords
#4I wonder how we force change with individual companies? Today I had to sign up for a UPS account. The password length was set to max 27 characters, and the form had disabled paste in the password field. Who do we lobby to get them to fail their next PCI-DSS compliance test?
Re: 300M Freely Downloadable Pwned Passwords
#5Re: 300M Freely Downloadable Pwned Passwords
#6I wonder how we force change with individual companies? Today I had to sign up for a UPS account. The password length was set to max 27 characters, and the form had disabled paste in the password field. Who do we lobby to get them to fail their next PCI-DSS compliance test?
Might happen in the next version release.
Re: 300M Freely Downloadable Pwned Passwords
#7Is it safe to test my password on this website? (because I just did)
"It goes without saying (although I say it anyway on that page), but don't enter a password you currently use into any third-party service like this! I don't explicitly log them and I'm a trustworthy guy but yeah, don't."
Safe: probably. Good practice: no.
Re: 300M Freely Downloadable Pwned Passwords
#8Is it safe to test my password on this website? (because I just did)
Re: 300M Freely Downloadable Pwned Passwords
#9Is it safe to test my password on this website? (because I just did)
If you only have one password to try, I'd say you have more important issues to tackle. Install a password manager, start using generated passwords, and stop using 'your password'.
Re: 300M Freely Downloadable Pwned Passwords
#10Going to generate a bloom-filter from this dataset tonight. Troy mentions some arguments against torrents, but it is better to have a authoritative torrent than none, imo.
I'd probably just shove the passwords into a database, limiting the index prefix to the first X characters to reduce index size.