300M Freely Downloadable Pwned Passwords
71–80 of 184 posts
Re: 300M Freely Downloadable Pwned Passwords
#72If I test my passwords, aren't they also now pwned?
Re: 300M Freely Downloadable Pwned Passwords
#73Earlier quoted context omitted.
salt "your password" with https://www.passwordcard.org/en
"Pick a password length. Eight is pretty secure and usually acceptable." Wait, what? Unless you're suggesting that I append this to a password.
Re: 300M Freely Downloadable Pwned Passwords
#74If I test my passwords, aren't they also now pwned?
Re: 300M Freely Downloadable Pwned Passwords
#75If I test my passwords, aren't they also now pwned?
Re: 300M Freely Downloadable Pwned Passwords
#76HIBP provides a REST API to check if a password has been found in a breach, Is there a disadvantage of using it in applications and restricting users not to use the breached password?
It's not ideal to send every new user's password to a 3rd party service.
Re: 300M Freely Downloadable Pwned Passwords
#77Re: 300M Freely Downloadable Pwned Passwords
#78Someone should apply deep learning to this and check how it compares with brute-forcing passwords. E.g. https://github.com/thoppe/5baa61e4c9b93f3f0682250b6cf8331b7e...
Re: 300M Freely Downloadable Pwned Passwords
#79Re: 300M Freely Downloadable Pwned Passwords
#80I wonder how we force change with individual companies? Today I had to sign up for a UPS account. The password length was set to max 27 characters, and the form had disabled paste in the password field. Who do we lobby to get them to fail their next PCI-DSS compliance test?
The password you create here can be used to access Online, Mobile and Telephone Banking.
All passwords must be six characters in length. Special characters (eg. *, %, $, etc) will not be accepted.