Maybe a soft-block of non-top10k would be okay then? You know the "somebody else is using your password" jokes might be useful eventually:-)
-
-
Does Google, Twitter, Facebook or your bank use any blacklists? Why/not?
1 reply 0 retweets 0 likes -
They use lists for lowering pw score, not technically a block list, though. My bank uses SMS OTP with PIN, my other bank allowed login=pw.
1 reply 0 retweets 0 likes -
Replying to @spazef0rze @thorsheim and
Michal Špaček Retweeted Michal Špaček
Czech post uses a minimal block list, with veeeery interesting choices... :-)https://twitter.com/spazef0rze/status/676700855681224704 …
Michal Špaček added,
1 reply 0 retweets 1 like -
Replying to @spazef0rze @thorsheim and
Google et al. have 2FA, list of devices, locations. Like you said, other serverside features, which I like a lot, more than a block list.
1 reply 0 retweets 0 likes -
Replying to @spazef0rze @thorsheim and
It's very rare you would choose a secure AND leaked-from-someone-else pwd. Most blocklist hits will be either nonsecure or personal reuse.
1 reply 0 retweets 2 likes -
Replying to @marcelsulek @thorsheim and
The question is: is a block list the right way how to teach users about secure passwords/accounts? Maybe but you block 3 pws & they go away.
2 replies 0 retweets 0 likes -
Replying to @spazef0rze @thorsheim and
It's another tool in the chain. First something like zxcvbn to filter too simple pwds. Then a blocklist to prevent reuse.
1 reply 0 retweets 0 likes -
Replying to @marcelsulek @thorsheim and
With 300M block list you'll probably block anything not generated in a pw manager. I see why Top1(0)k might be a better option. It depends.
1 reply 0 retweets 0 likes -
Replying to @spazef0rze @marcelsulek and
You're grossly overestimating the coverage of the 300M set. very_secure_password isn't in it. Try some passwords for yourself and see.
2 replies 0 retweets 1 like
Random non obvious words from the dictionary aren't either. Seriously, it's not that bad. I'm tempted to add /use/share/dict/words to it.
-
-
Replying to @marcan42 @marcelsulek and
Great :-) Checked some passwords cracked w/ http://crackstation.net dictionary: exoddus Tbvfs1 9plams P1ll3d Neznašov Just the 1st is there.
3 replies 0 retweets 0 likes -
Replying to @spazef0rze @marcelsulek and
Just 37% of /usr/share/dict/words is in it. Think of it as *common* words (and fictional character names, etc) plus *some* variations.
0 replies 0 retweets 0 likes
End of conversation
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.