Live data from Hacker News

300M Freely Downloadable Pwned Passwords

troyhunt.com

71–80 of 184 posts

Re: 300M Freely Downloadable Pwned Passwords

#73

Earlier quoted context omitted.

salt "your password" with https://www.passwordcard.org/en

"Pick a password length. Eight is pretty secure and usually acceptable." Wait, what? Unless you're suggesting that I append this to a password.

you can choose any area of the card, say 5 letters and a few keywords.

Re: 300M Freely Downloadable Pwned Passwords

#76

HIBP provides a REST API to check if a password has been found in a breach, Is there a disadvantage of using it in applications and restricting users not to use the breached password?

It's not ideal to send every new user's password to a 3rd party service.

you can still send the SHA1

Re: 300M Freely Downloadable Pwned Passwords

#79
post #71

If I test my passwords, aren't they also now pwned?

Not if you grep locally. How big is this data set? It can't be much bigger than a AAA video game download.

It's 11.9 GB of text (5.3 GB zipped). So smaller than quite a few video game downloads.

Re: 300M Freely Downloadable Pwned Passwords

#80

I wonder how we force change with individual companies? Today I had to sign up for a UPS account. The password length was set to max 27 characters, and the form had disabled paste in the password field. Who do we lobby to get them to fail their next PCI-DSS compliance test?

You think that's bad? My damn BANK has the following password policy for online banking:

  The password you create here can be used to access Online, Mobile and Telephone Banking.
  All passwords must be six characters in length. Special characters (eg. *, %, $, etc) will not be accepted.
Post reply on HN