4 ms·
Do you think the chances of false positives would make a bloom filter a bad choice for this?
by jdormit 9y ago
Do you think the chances of false positives would make a bloom filter a bad choice for this?
- Deimorz 9y agoIt's not ideal, but shouldn't be a big issue, since a false positive just means that you (very rarely) tell a user that a password is unacceptable when it should have been fine. That's a bit annoying for the user, but the result is that they just end up picking a different secure password. False negatives would be worse. Really though, a list of common passwords to block is such a small amount of data that it's probably best to just use an exact list. I can't see it being more than a megabyte or so.
- zwily 9y agoA "list of common passwords" isn't the guidance though - it's a list of passwords exposed in previous breaches. That list can be huge, and only practical to check with some efficient lookup mechanism.
- Deimorz 9y agoAh okay, sorry. I was thinking about it from the perspective of common passwords since that's something I've tried to find an existing bloom filter for before. I agree with you that Troy would probably be one of the best people to provide something like that. I wonder how feasible it is, that would be a really great resource to have available.
- zwily 9y agoYou can tune the bloom filter to have whatever false positive rate you think would be acceptable.