I implemented @troyhunt's HIBP password list as a pure Python3 Bloom filter, in 629MB (false positive rate = 0.0005)https://gist.github.com/marcan/23e1ec416bf884dcd7f0e635ce5f2724 …
-
-
And this is how I will be using it in production, on the
@euskalencounter reservations website. Comments welcome :)pic.twitter.com/al2DpM2z5P
10 replies 25 retweets 80 likes -
Where is the cleartext password hashed to sha1? Client side?
1 reply 0 retweets 1 like
Server side. There would be little to no benefit to doing it client side. Obviously SHA1 isn't used for storage, just the list.
8:12 PM - 4 Aug 2017
0 replies
0 retweets
0 likes
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.