5 ms·
Would it be a bad security practice to keep a database of the SHA hashes of maybe the 10 000 most common passwords then alert users who try to use them? Obvious
by git_SHA 9y ago
Would it be a bad security practice to keep a database of the SHA hashes of maybe the 10 000 most common passwords then alert users who try to use them? Obviously you would do the comparison before applying your actual bcrypt/PBKDF2 function with salt.
- OliverM 9y agoWouldn't it be easer to just test the submitted password against the 10,000 most common passwords directly, and refuse it then?
- proaralyst 9y agoWhich they already do; from the post: > Users cannot use any password matching a blacklist of the 10,000 most commonly used passwords.
- git_SHA 9y agoI read the post but somehow missed that. Sincere apologies.
- infogulch 9y agoMy question is, is 10k good enough? Wouldn't it be better to check against more? 50k?
- gwern 9y agoPresumably more is always better, but there's a very long tail of passwords so the hit rate will drop off a cliff, and now you're storing 5x as much data for increasingly questionable benefit.
- codinghorror 9y agothe problem is once you get to 10+ char passwords the common password list gets really tiny