I'm not aware of research that looks at behavior as blacklists grow larger. Pls share if you do! Also studied blacklists have been ad-hoc
-
-
Replying to @lakiw @TychoTithonus and
My gut is there's a point of diminishing rewards where large blacklists are annoying + the security is not worth it. But is it 1k, 1m, 100m?
3 replies 2 retweets 2 likes -
Replying to @lakiw @TychoTithonus and
The main usability frustration of blacklists is a user doesn't have knowledge of it before submitting their pw. Leads to (╯°□°)╯︵ ┻━┻
1 reply 1 retweet 3 likes -
Replying to @lakiw @TychoTithonus and
With small blacklists users might say, "Ok shouldn't have picked monkey". As BL grows, reject of user viewed "strong" pws cause frustration
4 replies 0 retweets 0 likes -
Replying to @lakiw @TychoTithonus and
1/2 the more I review pwd from
@troyhunt list, the more I agree with this statement. Many look very strong from the avg Joe PoV. So may be…1 reply 0 retweets 0 likes -
2/2… use a short list client side at pwd creation, and use the full list server side few times a year for auditing pwd and warning users.
1 reply 0 retweets 1 like -
3/2 (I'm working in a University, as sysadmin/CISO, I'm already auditing pwd and educating my users,
@troyhunt's list will help me here too)1 reply 0 retweets 0 likes -
You mean you store your users' passwords in plaintext so they can be audited offline?
1 reply 0 retweets 0 likes -
No, you take the plaintext version of troyhunt's list and use it a cracking dict against your AD or whatever system that is deployed
1 reply 0 retweets 1 like -
Your password hashing system is shit if you can afford to crack passwords like that without a bunch of GPUs.
4 replies 0 retweets 0 likes
(and even with GPUs, really)
-
-
With the hash I use it would take a couple years to audit all my passwords against troyhunt's list on a GTX1080, so not exactly viable.
0 replies 0 retweets 0 likesThanks. Twitter will use this to make your timeline better. UndoUndo
-
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.