I would advice against using such a massive block list, top 1K-10K is enough, & implement other serverside features instead. Better UX.
-
-
Replying to @thorsheim @marcan42
That interest me. You mean it is not good idea to ban setting any of public leaked passwords?
1 reply 0 retweets 0 likes -
Replying to @tomashala @marcan42
This is worthy of a paper, Twitter not sufficient. I imagine blocking 306 million pwds would cause massive customer loss & complaints.
3 replies 2 retweets 4 likes -
Password Creation in the Presence of Blacklists, USEC '17, http://www.passwordresearch.com/papers/paper650.html … Didn't measure such a large blacklist though.
1 reply 4 retweets 9 likes -
Replying to @PwdRsch @thorsheim and
And based on the 99.2% of Hunt's hashes I've cracked so far, if you simply require 12 characters minimun, 80% of his list is unnecessary.
2 replies 4 retweets 7 likes -
Replying to @TychoTithonus @PwdRsch and
And by setting minlength=12 and saying so on screen, UX but would be far better than being told «you can’t use that pwd Dave. Try again.»
1 reply 0 retweets 4 likes -
Replying to @thorsheim @TychoTithonus and
Except for all the people with 8-10 character passwords not in the blocklist which are perfectly adequate and would be rejected.
1 reply 0 retweets 0 likes -
Replying to @marcan42 @TychoTithonus and
... which is why you would tell them the minimum pwd requirements up front, *before* they are asked to set a pwd. Which is good UX.
1 reply 0 retweets 1 like -
Replying to @thorsheim @TychoTithonus and
The *vast* majority of possible 8-character passwords are not pwned; requiring 12-char passwords is IMO worse UX.
3 replies 0 retweets 0 likes -
Replying to @marcan42 @thorsheim and
And again, we don't need imho we need some evidence and science, oh wait here you go https://www.ece.cmu.edu/~lbauer/papers/2016/tissec2016-password-policies.pdf …
2 replies 1 retweet 1 like
Let me know when you find a paper about blacklist usage on a scale similar to the blacklist that was released just a few days ago.
-
-
*Everyone* is coming up with opinions because *none of us* has data. Which is why I intend to deploy it and gather some.
0 replies 0 retweets 0 likesThanks. Twitter will use this to make your timeline better. UndoUndo
-
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.