HIBP provides a REST API to check if a password has been found in a breach, Is there a disadvantage of using it in applications and restricting users not to use the breached password?
300M Freely Downloadable Pwned Passwords
41–50 of 184 posts
Re: 300M Freely Downloadable Pwned Passwords
#42Earlier quoted context omitted.
That's simply not true.
Yes it totally is true. Hashes are a standard length, and you can feed any length passphrase into the hash algorithm. It wouldn't surprise me to see passphrases limited to e.g. 256 chars anyway, but 27 smells very bad. What system limitation leads to this particular number? It smells like a DB column width to me.
Re: 300M Freely Downloadable Pwned Passwords
#43Earlier quoted context omitted.
That's simply not true.
Well, they're not wrong. Companies do store plaintext passwords as a customer service tradeoff. (A bad one, but they do it.) Chopping the length of a password to <32 chars is pretty correlated.
Re: 300M Freely Downloadable Pwned Passwords
#44Going to generate a bloom-filter from this dataset tonight. Troy mentions some arguments against torrents, but it is better to have a authoritative torrent than none, imo.
Re: 300M Freely Downloadable Pwned Passwords
#45Guessing it was in MySpace..
Ironically I used another password for sites I trusted less and that one isn't in there.
Re: 300M Freely Downloadable Pwned Passwords
#46Earlier quoted context omitted.
Well for that you can probably turn off JavaScript or use the web inspector to enable paste.
I can. My wife, who I've taught to use a password manager, probably can't. And neither of these excuses a 27 character limit that strongly suggests my password is being stored unencrypted somewhere.
If that conversation starts off at 1000 characters you're fine, but more often then not it looks more like:
"Make the requirement 8-12 characters"
"12 is too short"
"fine make it longer, like"
"Ok" [18 char implementation]
"Hey, Bob in accounting says he uses 20 char passwords"
"Fine, bump it by another 50%"
[27 char implementation]
[no further internal complaints]
[Specs never updated or reviewed again]
Re: 300M Freely Downloadable Pwned Passwords
#47> I'm envisaging more tech-savvy people using this service to demonstrate a point to friends, relatives and co-workers: "you see, this password has been breached before, don't use it!"
But I can't be the only one whose family would be baffled by the term "pwned". I wish it said something like "Your password has been hacked!" which we all know not to be technically correct but would resonate a lot more.
Re: 300M Freely Downloadable Pwned Passwords
#48Earlier quoted context omitted.
Well, they're not wrong. Companies do store plaintext passwords as a customer service tradeoff. (A bad one, but they do it.) Chopping the length of a password to <32 chars is pretty correlated.
and storing plaintext passwords is unacceptable.
Re: 300M Freely Downloadable Pwned Passwords
#49Earlier quoted context omitted.
Well, they're not wrong. Companies do store plaintext passwords as a customer service tradeoff. (A bad one, but they do it.) Chopping the length of a password to <32 chars is pretty correlated.
Also for integrations with other, often older, systems.
Re: 300M Freely Downloadable Pwned Passwords
#50I wonder how we force change with individual companies? Today I had to sign up for a UPS account. The password length was set to max 27 characters, and the form had disabled paste in the password field. Who do we lobby to get them to fail their next PCI-DSS compliance test?
Don't Fuck With Paste: https://chrome.google.com/webstore/detail/dont-fuck-with-pas...