I implemented @troyhunt's HIBP password list as a pure Python3 Bloom filter, in 629MB (false positive rate = 0.0005)https://gist.github.com/marcan/23e1ec416bf884dcd7f0e635ce5f2724 …
Except for all the people with 8-10 character passwords not in the blocklist which are perfectly adequate and would be rejected.
-
-
... which is why you would tell them the minimum pwd requirements up front, *before* they are asked to set a pwd. Which is good UX.
-
The *vast* majority of possible 8-character passwords are not pwned; requiring 12-char passwords is IMO worse UX.
- Show replies
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.