I implemented @troyhunt's HIBP password list as a pure Python3 Bloom filter, in 629MB (false positive rate = 0.0005)https://gist.github.com/marcan/23e1ec416bf884dcd7f0e635ce5f2724 …
The *vast* majority of possible 8-character passwords are not pwned; requiring 12-char passwords is IMO worse UX.
-
-
If requiring 12 character passwords made UX sense then why isn't every website doing that already?
-
Legacy systems. Cost. Lack of knowledge. Laziness. Lack of business case or risk analysis to support the change. Standards. Even laws.
- Show replies
New conversation -
-
-
Heh. I've got rainbow tables for LM that will crack almost anything <=14 characters. Your statement needs more context, like hash algo etc.
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
-
-
And again, we don't need imho we need some evidence and science, oh wait here you go https://www.ece.cmu.edu/~lbauer/papers/2016/tissec2016-password-policies.pdf …
-
Interesting. Imposing one random passphrase was still a UX challenge. Maybe present user with ten random phrases, and let them pick?
- Show replies
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.