I think we're agreed: 320M blacklist is suboptimal. Instead, check common dicts & passwords, masks, length, & let user select random phrase
You mean you store your users' passwords in plaintext so they can be audited offline?
-
-
No, you take the plaintext version of troyhunt's list and use it a cracking dict against your AD or whatever system that is deployed
-
Your password hashing system is shit if you can afford to crack passwords like that without a bunch of GPUs.
- Show replies
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.