2/n Zxcvbn default blacklists: 100k english words from wikipidia, ~100k names (first + last), 47k common passwords, 39k words from tv & film
-
-
Replying to @lakiw @TychoTithonus and
3/n Zxcvbn checks for mangled variations of its blacklists. Aka could easily be said it has over 300mil blacklist depending on configuration
1 reply 1 retweet 0 likes -
Replying to @lakiw @TychoTithonus and
4/n What I think makes Zxcvbn different from using Troy Hunt's list though is that it attempts to explain why a password was rejected aka UX
1 reply 1 retweet 0 likes -
Replying to @lakiw @TychoTithonus and
5/n Much longer way of saying the disagreement might not be on size of blacklist but the user's experience with the blacklist ;p
2 replies 0 retweets 1 like -
Replying to @lakiw @TychoTithonus and
6/n Or I guess it could be interpreted that Zxcvbn is overkill for most online password guessing threats ;p
1 reply 0 retweets 0 likes -
Replying to @lakiw @thorsheim and
Depends on sophistication of the defender. A low-and-slow bruteforce from a million-node botnet may not be detected by some mid-tier orgs
1 reply 0 retweets 1 like -
Replying to @TychoTithonus @lakiw and
Especially when each IP does only one or two probes.
1 reply 0 retweets 1 like -
Replying to @Hydraze @TychoTithonus and
Akamai published some good data from a real attack like this earlier this year: https://www.reddit.com/r/Passwords/comments/5qv5pw/blocking_online_password_guessing_attacks_when/dd2bgo3/ …
1 reply 3 retweets 4 likes -
+1 "A threshold of 5 invalid login attempts per source IP over a 60 minute period […] allows them to block 99.69% of botnet login attempts"
2 replies 1 retweet 0 likes -
Replying to @TychoTithonus @PwdRsch and
If I did that I'd get royally screwed by CGNAT, which is very common these days. It's a massive risk in my use case (login is critical).
1 reply 1 retweet 1 like
My use case is two phase. I can afford to annoy users on login week 1, but not week 2. So forced PW change=OK, ratelimit=danger.
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.