25 ms·
"Pwned Passwords" V2 With Half a Billion Passwords
- NuSkooler 9y agoAnyone happen to have a diff of say the top 10k vs the previous release?
- roymurdock 9y agoBit off topic, but I was searching for a better way to manage passwords a few weeks ago (rather than have 1 or 2 master passwords across all websites). I found KeePass through an old ask HN thread. It's a great little free, open source key/password storage app that works across all my devices (iOS, macOS, windows). https://keepass.info/ https://keepass.info/ I'd be interested to hear any suggestions for similar apps I could recommend to my parents, who expressed concerns about their online passwords. KeePass would be the ideal solution, but I don't think it would hold their hand through download, setup, and password generation enough to be 100% ideal. Any suggestions?
- sebazzz 9y agoKeepass works great, but one disadvantage is that you cannot you additional credentials providers if you want to open your database on other devices. For instance, if I would use a Yubikey provider, I cannot open the database on my iPhone. It would be great if the authentication providers can be configured in an 'or' instead of an 'AND' (this means convenience vs security). So on Windows, with my Windows account or perhaps Hello it unlocks my Keepass database and perhaps use a Yubikey, but on my iPhone I'm still required to enter a password. But unfortunately, the current implementation combines the authentication providers to create a combined encryption key. But still, Keepass is easy to setup and maintain. Just put your database on your favorite cloud provider (if you want to take the risk) or manually sync it to your phone and you got the righty credentials everywhere at hand.
- Spooky23 9y agoOne way to address this is to have a long term vault that doesn’t get edited often and a working vault.
- whitepoplar 9y ago1Password is fantastic.
- deleted 9y ago[deleted]
- bllguo 9y agoI've used Lastpass for awhile, and so does my work. Recently I switched to Bitwarden partly because of security concerns, partly because it's open source, but mostly due to Firefox moving to WebExtensions. They both have free options!
- BugsJustFindMe 9y agoHow recently? Because https://addons.mozilla.org/en-US/firefox/addon/lastpass-password-manager/versions/ https://addons.mozilla.org/en-US/firefox/addon/lastpass-pass... shows "Compatible with Firefox 57+" since early November.
- bllguo 9y agoThere was no compatibility when I switched, and I waited for some time (I use Nightly). Maybe "recent" is misleading.
- m_st 9y agoHave a look at 1password.com and their family plan, so you can admin your parents too, in case they forget their master password. Can’t recommend this enough. Edit: If that helps, Troy Hunt and other security guys are also using 1password (even the cloud solution).
- sachleen 9y agoLong time lastpass user recently switched to BitWarden. I find it's UI to be cleaner/easier to use
- ibdf 9y agoMy biggest frustration with lastpass is that it doesn't seem to know the difference between subdomains, so it suggests several passwords for the same domain even though I am on different subdomains.
- y4mi 9y agoThere was an option somewhere with which you could disable that one url at a time. I never bothered with it though and recently switched to keepass, so can't verify anymore.
- xeonoex 9y agoHow is BitWardens UX on mobile? Does it support autofill and automatically adding/updating passwords you enter on apps or the browser?
- JoshTriplett 9y agoThe Firefox password manager, combined with Firefox Sync, works across Windows, Mac, Linux, iOS, and Android.
- 667 9y agoBeen using this a few years, it's really good from user standpoint.
- ythn 9y agoAlgorithmic password in your head, with a google spreadsheet to keep track of usernames, password rules, etc. on a per site basis (i.e. "bankofamerica, ythn.smith@gmail.com, 4-12 characters - no special). Edit: downvote away, but so far no one has ever been able to give a compelling reason why algorithmic passwords are bad. It has tradeoffs, sure, but so do password managers.
- pbhjpbhj 9y agoIf a couple of your algorithmic passwords get leaked, attached to same email, then the algo could be guessed and you potentially lost all your accounts.
- ythn 9y agoThat's a lot of unlikely ifs. And that also assumes my algo is easy to reverse from 2 digests. My counter to that is that it is unlikely anyone would specifically target me and waste resources trying to crack my algorithm when there is so much low hanging fruit elsewhere. If I am specifically being targeted, I've probably already lost, even if I use a PW manager. Compare to PW managers: "If your password db and master password get leaked, attached to the same email, then you lost all your accounts." Also with PW manager, losing your phone can mean Denial-of-Service to all of your accounts if you are i.e. travelling.
- pbhjpbhj 9y agoOther methods being poorer doesn't make your method objectively better. You're probably right on low-hanging fruit, all depends on your threat model I suppose. Don't password managers have 2FA, and alternate phone numbers?
- ythn 9y agoThere is no method that is objectively best. Every single current method has tradeoffs. Being cumbersome to setup/use/recover is a big tradeoff of PW Managers.
- baxtr 9y agoActually, I’m pretty happy with the integrated iOS password manager. They also feature app support now. Works like a charm for me
- ovao 9y agoHappily, too, Safari’s suggested passwords have pretty good entropy and are sensible enough to be accepted by many password rulesets.
- fiatjaf 9y agoI don't trust myself enough to keep track of a local database of passwords, because of that for years I sticked to the tactic of repeating the same 2~3 passwords over and over on all websites. Now I'm using https://lesspass.com/ https://lesspass.com/, a deterministic password generator that requires no setup besides installing a browser extension[1] and doesn't requires me to keep a database or run any other custom programs. [1]: There's the official extension for all browsers, but I've developed my own, https://lesspass.alhur.es/ https://lesspass.alhur.es/, which solves 99% of the problems associated with the whole LessPass idea.
- ythn 9y agoHow does lesspass handle password rules? i.e. one site allows special characters, others don't? Or say one of your passwords gets compromised and you need to change it. It doesn't seem like lesspass would be able to do so without a db.
- stordoff 9y agoI've been trialing it recently on sites of lesser importance, and in the configuration OP described, it doesn't - everything is deterministic from login+site+master password. It does however you set password profiles, which alter how the password is generated. Here's an abridged example from their FAQ[0] with my notes about what each option does: "login": "contact@lesspass.com", # User name "site": "example.org", # Domain name "lowercase": false, # Site accepts lower case characters (Default: true) "uppercase": false, # Site accepts upper case characters (Default: true) "symbols": false, # Site accepts symbols (Default: true) "numbers": true, # Site accepts numbers (Default: true) "counter": 1, # Increment e.g. on compromise and the generated password is changed (Default: 1) # Password entropy is derived from pbkdf2, counter is used as part of the salt "length": 8, # Password length to be generated (Default: 16) In the default configuration, these profiles are stored in the browser's local storage, so lost if/when that is cleared. LessPass provide a service to store these profiles on their server (log-in is generated from the master password using a default password profile), and provide the scripts (Docker) that let you self-host this data (the browser extensions include a field to set server domain). For me, it's a useful balance of convenience and security (each site gets a strong unique password, but I can regenerated them on devices where I haven't synced a password DB) vs. KeyPass which I was previously using. I'm probably going to switch to 1Password thought - it gives the same "any device" benefits, has basically the same risk model (compromise of the master password is a full-compromise, and because I need the synced profiles I need to put _some_ trust in a third-party anyway[1]), but it gives me the full flexibility of a real password manager (store associated data, credit cards, set specific passwords if needed etc.) [0] https://github.com/lesspass/lesspass/wiki/FAQ https://github.com/lesspass/lesspass/wiki/FAQ [1] 1Password: need to trust their client isn't malicious/capturing the password at login and is secure; LessPass: need to trust the webclient is never changed to exfil. the master password, (theoretical?) risk of brute-forcing master password from a generated password, and sends sites/username metadata to a largely unknown third party (could run my own server, but it would likely get neglected and fall behind on security updates etc.).
- y03a 9y agoJust keep in mind anything simpler likely has additional attack surfaces. e.g. Anything that's cloud based, browser plug-in, centralized, etc. all bring the standard attack surfaces in that domain. Still, it's probably better than what most people do, same user name/password combo everywhere.
- chrislomax 9y agoAgain, 1Password. It allows you to login to multiple workspaces so you can have your family plan and your work team plan at the same time. There is a cost but I can guarantee that it’s saved me more in time than the cost could ever amount to. I’ve never used an insecure password since using it. All completely random and it’s so easy to use. The different vaults means I can grant my little boy access to the stuff he uses whilst having my credit card and server details in other vaults without fear that he can access them (more the credit card details). I just need to get the wife into using it now...
- __jal 9y agoI love 1Password and have used it for years. But be aware that they are moving to cloud storage for password data. At this point, you're not forced in to it (and they've made no concrete announcement yet), but that's pretty clearly where they want to go. Perhaps that's acceptable to you; I'll be moving off at that point. But in any case, it is something to be aware of when choosing something like this - moving between password managers is a hassle.
- angerbot 9y agoHave you read their security white paper[1]? As much as I tend to freak out about cloud storage of password data (one reason I moved off of lastpass), they do seem to take fairly strong steps to host-proof the data (such as having an on-device generated secret key that they never receive). [1]: https://1password.com/files/1Password%20for%20Teams%20White%20Paper.pdf https://1password.com/files/1Password%20for%20Teams%20White%...
- __jal 9y agoI did read it. For me, it doesn't matter for two reasons. Professionally, I have a policy to comply with. And personally, I don't use other peoples' machines for personal storage, period. So why would I want my (even well protected, assuming 1PW didn't make a mistake) passwords to be an exception?
- Spooky23 9y ago
- funkymike 9y agoI've tried to get my mom to use KeePass with limited success. To her having her easily guessable passwords written in a little notebook next to the computer is fine. I think a prerequisite is getting buy in on the idea that passwords need to be treated like the keys to your house or your bank account numbers.
- p1necone 9y agoAs far as I'm concerned writing passwords in a notebook in a draw or something is fine. The easily guessable part not so much. If someone has physical access to your computer in the first place there's lots of things they could do.
- SteveJS 9y agoI was looking at Dashlane which seemed to have some good features, including some ability to do password rotation automatically, and some level of yubikey support. That said I'm still using keepass. I discovered it when I needed a solution that worked on an original Surface RT, as well as an iphone, and I've remained happy.
- PuffinBlue 9y agoNow Dashlane seems to have in browser apps and finally supports Linux, I'm looking at moving away from Lastpass. Between them and BitWarden there seems to be quite good options form Linux users now. If anyone is a DashLane/BitWarden user and wants to chime in with their experience them that would be much appreciated.
- doublerebel 9y agoI love Dashlane, and the Linux support is solid through the browser extension. Dashlane has the best interface across devices, of all the password managers I've used. The password sharing feature is great for business. Sure, it's a cloud service, but it's polished enough that I can get non-tech people like my family and coworkers to actually use it. Lastpass did not pass that test. I use Dashlane every day on Mac, Linux, Windows, and Android.
- PuffinBlue 9y agoThanks. One question I have - can you turn off auto-login globally or just on a per website basis? Docs seem to imply on a per site basis only but that seems a bit odd. I'm wondering how DashLane handles multiple logins for the same service (Google/GitHub etc etc).
- doublerebel 9y agoI'm not sure about the global option, I've never tried. For multiple logins on the same service/domain, it presents a clickable/tappable list.
- qznc 9y agoI'm a heavy KeePass user in private and I like it. Recently, I was pleasently surprised that my new corporate IT overlords allow me to use it at work too. Password generation is fine. Whenever you create a new entry it prepopulates it with a generated password. Just type in domain and username and hit ok. On the negative side, KeePass UI is old school. Lots of buttons and options. Not streamlined for the common use cases. (No comment on download and setup, since I'm not a Windows user)
- yarwelp_ 9y agoOn the topic of passwords, have a look at my command-line passphrase generation program. GitHub: https://github.com/ctsrc/pgen https://github.com/ctsrc/pgen It's written in Rust. Install the Rust toolchain installer from https://rustup.rs/ https://rustup.rs/ curl https://sh.rustup.rs -sSf | sh And remember to add ~/.cargo/bin to your PATH. Then install my command-line utility cargo install pgen Usage is described in detail in the README on GitHub. Additionally you can ask the program itself for a brief help summary. pgen --help Eventually pgen will be available in some package manager repos so that you can use your preferred package manager to install pgen but until then it must be built from source following the steps above.
- dmitrygr 9y agoA personal question. Do people really install megabytes of dependencies to run what would be a one line shell script, were it written in shell?
- Pxtl 9y agoMental bandwidth is more expensive than megabytes, so yes.
- tomsmeding 9y agoYou wouldn't manage that with a one-line shell script, assuming that you want to format it reasonably. :) I do agree that having to install loads of things for a simple tool is overkill, but I'd wager the actual binary produced doesn't have many dependencies (I'd expect just libc, in fact); so would this at some point land in a package manager, your life will improve.
- kbenson 9y agoWell... CHECKPW="p@ssword" SHA1=`echo -n "$CHECKPW" | sha1sum`; curl -s https://api.pwnedpasswords.com/range/${SHA1:0:5} | grep -i ${SHA1:5:34}
- 9y ago
- groovecoder 9y agodo not skip the section on "Cloudflare, Privacy and k-Anonymity" ... it is a great summary of an elegant privacy solution. And check out Cloudflare's detail post too: https://blog.cloudflare.com/validating-leaked-passwords-with-k-anonymity/ https://blog.cloudflare.com/validating-leaked-passwords-with...
- jkaptur 9y agoI'm a bit confused - why not distribute a serialized Bloom filter representing these passwords? That would seem to enable a compact representation (low Azure bill) and client-side querying (maximally preserving privacy).
- fhenneke 9y agoA Bloom filter with >500M items, even when allowing for a comparatively high rate of false positives such as 1 in 100, is still in the hundreds of MBs, which would not be that much more accessible than the actual dump files.
- KMag 9y agoThe compressed archive here is over 8 GB. An uncompressed 2 GB Bloom filter with 24 hash functions and half a billion entries has a false positive rate of less than 1 in 14 million. 75% space savings, with no decompression necessary for use, and a 1 in 14 million false positive rate is nothing to sneeze at.
- rrobukef 9y agoBut no count of how often the hash is used. Counting bloom filters are till a bit harder to implement.
- KMag 9y agoCounting bloom filters are only marginally more difficult to implement. To increment a key, find the minimum value stored in all of the slots for the key, and then increment all of the stored values for that key that are equal to the minimum value. To read, return the minimum value for all of the values stored in slots for the key. For these purposes, however, you probably instead want to store just separate Bloom filters for counts above different thresholds, since the common use case would be accept/reject decisions based upon a single threshold.
- scrollaway 9y ago[Pasting an old comment of mine on password managers, since I see people talking about starting to use Keepass. I hope this helps someone] ---- If you're just starting, here's some guidance on setting up a password manager. First of all: Don't be afraid of using one. It's not just more secure, it's super convenient. Never again will you ask yourself: Did I make an account for this website/service? What email did I use? Never again will you have to remember a password. Using a password manager is a quality of life improvement. KeepassXC is what I recommend to people at this point. It's free and you own your data (your passwords). They live wherever you want them to live. There are plenty of online services that are supposedly more convenient but I have to say I trust them less -- YMMV (1Password is the best I'm aware of). https://keepassxc.org https://keepassxc.org If you do use keepassxc, you get the added benefit of being able to store 2FA settings in it as well (if you store them in the same database as your passwords, be aware that you lose the security benefit of a second factor, however it is still more secure than not having 2FA enabled due to the One-time password component). Put every account you ever made and ever make into keepass. Enable 2fa wherever you don't have it enabled. Add login URLs and notes. Generate your passwords from keepass itself; the password generator is really powerful and lets you very easily deal with site-specific shitty password limitations. I'm telling you this because, seriously, it's incredibly convenient to have this stuff as long as you're rigorous about maintaining it. Oh, also, keepass has the full history of all your passwords. Need to look up an old password? Go into details and look at "History". You can also attach files to items (items don't have to be accounts at all, you can use keepassxc as a simple encrypted storage db). Mobile support: Keepass2Android. Best android client, with google drive support. iOS I have no idea, suggestions welcome. IMPORTANT: BE STUPIDLY PARANOID AND RIGOROUSLY CAREFUL ABOUT YOUR MASTER PASSWORD. That thing, together with your keepass database, unlocks all your accounts ever. Use a really long passphrase that you will never have to write down (if you do decide to write it down because you don't trust yourself, store it in a safety deposit box, don't put it in a bloody drawer). Make sure the device you unlock the database on is malware-free. PS: Wondering what's up with Keepass vs. KeepassX vs. KeepassXC? Keepass is the original app, written in .NET but with poor multi-platform support. KeepassX is a rewrite in Qt and is a fantastic password manager, but has gone unmaintained recently. The open source community picked up the slack in the KeepassXC fork (after continuing countless attempts to upstream the patches) and has implemented lots of powerful features. I've switched to it and at this point I strongly believe it's the better client.
- hosh 9y agoThis dataset would be a fun project to implement on IPFS -- content-addressed, distributed database of leaked passwords using the same hash range protocol.
- zaroth 9y agoI'm going to have to disagree with the premise that sites should stop users from choosing a password which happens to have been cracked offline at some point in the past -- to the tune of blacklisting half a billion potential secrets. What exactly is the end goal, and at what cost? Well, there are 3 ways to steal a password. You can steal it from the user -- either by phishing or with malware -- in which case it matters not a bit how complex the password is. You could attempt to crack it online, that is, by attempting to login as the user through the front door. In this case, a simple counter should limit the number of attempts before a second factor is required, such as clicking a link in an email, and a list of half a billion candidates isn't going to help here either. Finally, you can steal the password verifier database and attempt to crack the password offline. So, the theory must be that passwords in a known attacker's dictionary are more likely to be used as candidates in an offline attack. This is likely true. But once the verifier database is stolen, if an attacker is able to run the password hashing function, then every password which is not raw entropy already must be assumed to be cracked. Regardless of how hostile your password policy is. So what exactly is this policy saving you? On the flip side, it's reasonable to ask, what would such a policy cost you? It's hard to say without actual data, but I'd love to see some data on what percentage of candidate passwords offered by a user trying to signup on their mobile device would be rejected under this policy? How many attempts on average would it take a user to find a password which was not rejected? And what's the increase in bounce rate, and therefore lost signups, that would result? How many increased password resets would be required from users choosing passwords that they inevitably don't remember? How many additional lock-outs which require customer support capital to resolve? Password policies on average are pretty horrendous. But password policies which are arbitrary black boxes to the end user are about the worst you can find. Sitting on my mobile device, not knowing if a chosen password will be accepted, having to type it twice each time, is a wretched user experience which would need extremely lofty benefits to outweigh the cost. I fail to see any benefits to this approach which couldn't be solved with better hashing which wouldn't impact the user experience whatsoever. I'll say one more thing on the idea of blacklists. Users just trivially work around them. Password quality (entropy, guessability) does not generally increase. Bad password policies often decrease password quality, particularly in the case of password expiry. But a frustrating opaque blacklist could be just as bad. (I'm not aware of any studies on this). An attacker who knows a particular blacklist was in place will use munging rules to find derivatives from the master list which are not on the blacklist. How much will their crack rate (percentage of clears recovered from an offline attack of a given magnitude) be affected? But more importantly, potentially driving down the crack rate through user hostile password policies is a game which has huge dividends at first (getting a password which can't be attacked online) and very little dividends after that point. Disclaimer: Founder of BlindHash, which is the "better hashing" I refer to above.
- orasis 9y agoCan someone please just provide the exact shell commands to generate a compatible sha-1 of a password to grep against the database? The article seems to ramble forever about how to perform online checks without discussing the basic offline secure option.
- benbristow 9y agohttp://onlinemd5.com/ http://onlinemd5.com/ Just uses JavaScript in the browser
- mnutt 9y agoI wouldn't recommend using this. Even if you were to read the page source and see that it is in fact not sending data back to a third party, either a) the site owner could change this in the future, or b) you could be man-in-the-middle'd since they're using http, or c) one of the third party scripts they run on that page could either accidentally or intentionally take your password. Don't put your password in there.
- ianlevesque 9y agoecho -n "password" | openssl sha1 | tr '[:lower:]' '[:upper:]'
- default-kramer 9y agoI thought it was funny that toepoke thought "People won't know what 'pwned' means." So instead they inform the user that they have a "Pawned password."
- dopamean 9y agoAn old password (12 char numbers and letters) I've since stopped using (but used to use everywhere) appears as pwned in this list (3 times!). I'd love to know who exposed it. Any chance I can find out?
- czardoz 9y agoYou could check for your email on https://haveibeenpwned.com/ https://haveibeenpwned.com/
- anitil 9y agoAs a policy Troy Hunt won't reveal which breach he found your data in. I considered setting up a series of 'canary' emails so that I could track who's selling what but ... well never got round to it.
- giarc 9y agoYou used to be able to adjust your email address to check. For example if you email was bill@gmail.com, you could sign up for HN with bill+hackernews@gmail.com. Gmail ignores the part after the + sign. Therefore if you noticed emails coming to that address, you would know that HN sold their list. However, I've found that most forms reject that as a non-valid email address now.
- outworlder 9y agoYes. Those forms are also ignoring relevant RFCs.
- deleted 9y ago[deleted]
- emmelaich 9y agoCan you be more specific?
- 9y ago
- deleted 9y ago[deleted]
- schmich 9y agoA quick Ruby script to check if a password has been compromised using the Pwned Passwords V2 API: https://gist.github.com/schmich/aeaffac922271a11b70e9a79a5fee19c https://gist.github.com/schmich/aeaffac922271a11b70e9a79a5fe...
- amatecha 9y agoHmm this is a pretty great list to use for any service that has user signups -- disallow signup when using a password that is known to have been "pwned"! :)
- deleted 9y ago[deleted]
- quickthrower2 9y agoOh the shame! An important password of mine is pwned. Just had to change it.
- hmexx 9y agoI just tried a 11 character password without special chars, that I’ve used on over 50 sites, over the last decade. It’s my password for throaway websites. Some pretty dodgy. Not in the database. Makes me feel pretty good about password security overall!
- empath75 9y agoI have a password that’s a pair of words in two languages with some number substitution that I use a lot on websites I don’t care about and it’s not in the dB. And I’m sure I’ve used it on sites that have been hacked, so I dunno.
- dingo_bat 9y agoI think many websites that got hacked leaked email addresses cc info etc, but most do not store passwords so your password wasn't leaked in plaintext.
- ianlevesque 9y agoUnless the site was also storing in plaintext they’d have to actually crack the password hash too, which for some passwords is very hard to do.
- seanalltogether 9y agoI just checked my very obscure 9 character password I use only for financial websites, and it appears 3 times.
- vinchuco 9y agoinsert the mathematical joke about the half-black sheep
- lzybkr 9y agoHere is a quick PowerShell script - it supports the pipeline so you can automate, e.g. if you use a command line password manager. https://gist.github.com/lzybkr/85b4dbd6536ea5351e8d8e492a432030 https://gist.github.com/lzybkr/85b4dbd6536ea5351e8d8e492a432...
- Satchelmouth 9y agoThank you
- danbruc 9y agoNow it is to late, but Base64 could save about a third of the bandwidth, maybe for V3. EDIT: Not if compression is enabled as mentioned in the article, so forget about that.
- jack6e 9y agoHow do I submit a pull request on Github asking that "hunter2" be removed from his list?
- LeonM 9y agoFor those who missed the hunter2 reference: http://bash.org/?244321 http://bash.org/?244321
- deleted 9y ago[deleted]
- kbenson 9y agoThat moment when you test an old, but still highly valued and securely used, password that you think isn't super obscure but not likely to be used much and see a 4000+ count...
- royce 9y agoAnd that's exactly why using this entire corpus - or even more than the first few tens of thousands - as a blacklist would be an extremely user-hostile choice [1]. Password psychology is remarkably consistent across a given demographic, because most people start by modifying of one or more base tokens that are already stored in memory because of their personal significance. So unless the implementation gives specific, real-time UX feedback to teach users how to pick a password that is very unlikely to be in this (and future, ever-growing) versions of this corpus, using a large blacklist is "gotcha infosec". It creates UX where the user cannot possibly come up with a "good" password using most of their previous strategies. It's the worst kind of "gotcha infosec". 1. https://news.ycombinator.com/item?id=16434266 https://news.ycombinator.com/item?id=16434266
- Arn_Thor 9y agoThat moment when you test a very unique password you used to use and it's been pwned once.. GULP! Glad I stopped using that one
- filoeleven 9y agoSame experience here, except mine was current until shortly after I checked it. The weird part is that I only used it on internal systems at work. With an overly paranoid security department. Either they’re paranoid in the wrong ways, or I have an evil twin somewhere. At least, I hope they’re the evil twin...
- Arn_Thor 9y agotime for some soul-searching
- woolvalley 9y agoI know you can't search username+.*@gmail.com addresses on have I been pwned, but it would be pretty useful if we could.
- ShakataGaNai 9y agoA quick python script to hit the API, for those that don't want to use the webform (rightly so): https://gist.github.com/ShakataGaNai/cb786a2c64abc83d4dbe0dbf6b60a5e3 https://gist.github.com/ShakataGaNai/cb786a2c64abc83d4dbe0db...
- kbenson 9y agoOr, for those that don't want to use Python (in case it isn't installed, or requires a non-core module, I dunno) but have access to a Linux box: # echo -n "password" | sha1sum 5baa61e4c9b93f3f0682250b6cf8331b7ee68fd8 - Take the first 5 characters, in this case "5baa6" and use at the end of the API endpoint in your browser. E.g. https://api.pwnedpasswords.com/range/5baa6 Then take the all the rest of the hash after the first 5 characters, in this case "1e4c9b93f3f0682250b6cf8331b7ee68fd8" and ctrl-f search the results page for it.
- wuunderbar 9y agoFor ease: # echo -n "password" | sha1sum | cut -b 1-5 5baa6
- kbenson 9y agoYeah, but you would need two commands then, because you need to search for bytes 6-40 in the resulting output. I made a one-liner farther down the comments.[1] 1: https://news.ycombinator.com/item?id=16434244 https://news.ycombinator.com/item?id=16434244
- royce 9y agoThe UX of a blacklist with a half billion entries would be so crippling that it would cause a user revolt. Most people's password-selection strategies are similar enough to other people's (like kbenson's 4000+ hit) that they could spend hours trying to come up with a password that has never been leaked before. I tried to encourage Troy to suggest to implementors that blacklisting all passwords was a Bad Idea. Instead, he doubled down: https://twitter.com/TychoTithonus/status/966400790221930496 https://twitter.com/TychoTithonus/status/966400790221930496 Please don't use the entire list for blacklisting unless you actively also guide the user in how to generate a random passphrase (if a human must remember it) or a random password (if it will be stored in a password manager). Instead: 1. Use a high-level password-strength assessment widget like zxcvbn: https://github.com/dropbox/zxcvbn https://github.com/dropbox/zxcvbn 2. Configure a blacklist with, say, 10K or 20K of the most common passwords. 3. Hash passwords with bcrypt cost 12 (adjusted to your platform's hashrate capabilities), scrypt, or the appropriate method from the Argon2 family. But for all that is holy, please don't use Troy's entire corpus - or even the first million - as a blacklist. To quote the old NANOG saw, I encourage all of my competitors to use it. ;) Edit: And since Troy's API at this writing does not support only querying the top X passwords, there's no way to use the API while avoiding the UX nightmare. So if you want to use this data in a professional manner, but don't want to download the entire corpus, here are the first 20K from his list (of which I've only personally cracked 19965 so far, interestingly; gist will be updated once I get all 20K): https://gist.github.com/roycewilliams/281ce539915a947a23db17137d91aeb7 https://gist.github.com/roycewilliams/281ce539915a947a23db17... Edit 2: Preliminary results indicate that this data may be dirty. The 273rd most common password, according to Troy, is '$HEX'. This is almost certainly an import/conversion artifact, since the '$HEX' prefix is how most cracking suites escape non-ASCII or passwords that contain colons. I expect that there will be more artifacts. Use the data with caution.
- kbenson 9y ago> I tried to encourage Troy to suggest to implementors that blacklisting all passwords was a Bad Idea. Instead, he doubled down > Please don't use the entire list for blacklisting unless you actively also guide the user in how to generate a random passphrase (if a human must remember it) or a random password (if it will be stored in a password manager). I think he did the right thing, and think you are correct as well. I think we have the best of both worlds with this, in that it includes the count, so API users can determine what the correct cut-off is for them. Once you get into the thousands (or maybe less) might be a good indicator that your password is not only relatively common, but also likely to be on (and maybe even fairly high on) many dictionary lists. More secure services that cater to more technically savvy users (or security conscious companies) may decide to blacklist any password on the list period, and that may be okay because those sites either trust their users to deal with it or can dictate conditions for a captive audience.
- odammit 9y agoIf you spend the time building a system to search those half billion passwords when you’re users are signing up, you should focus on building a login rate limiting system so it’s not possible to brute force someone’s password.
- royce 9y agoThe purpose of a blacklist is multifold - to reduce the efficiency of an offline attack, in which the hashes are stolen and can be attacked at high speeds without rate limiting - as well as an online attack.
- odammit 9y agoSure and 10k will do fine otherwise “! I thh Cher;457?:25?//(5 we” is going to suck for you user login story. Maybe salt your passwords, use some stretches, and a decent algorithm instead of MD5, SHA1, etc. Also stay up on algorithms and roll your users over to new ones over time.
- ravenstine 9y agoI think this is intended for the case where a database has been compromised, but then again, I thought that hash algorithms and salting were supposed to deal with that.
- MBCook 9y agoIF people actually do that correctly, yes. But history has proven many sites (big and small) are quite happy to send you your plaintext password.
- odammit 9y agoAlthough it does happen that’s amature and unacceptable. Either you have some EXTREME legacy or lazy engineers. Doing it right doesn’t take long.
- rphlx 9y ago
- ivanech 9y agoI think it would be interesting to do an art project with this data - some of these passwords are funny and/or revealing. Some examples: pooplasagna - 3 times eggsarebad - 3 times eggsaregood - 25 times myhusbandcheats - 4 times icheatonmywife - 1 time ihatemyneighbors - 2 times iamanalcoholic - 6 times 1yearsober - 31 times imissmykids - 51 times imissmyparents - 6 times
- deleted 9y ago[deleted]
- fny 9y agoilovemymom 20141 ilovemydad 7850
- sid- 9y agomoms are loved almost 3 times more.
- swiley 9y agoOr people who love their moms are 3 times more likely to choose a bad password.
- irrational 9y agoPeople who love their moms are less intelligent than those who love their dads? There is a dissertation in psychoanalytics just waiting to be written.
- cypherpunks01 9y agoI think it lines up well with existing theories, that of the oedipal complex combined with the idea that women are smarter.
- kirillkh 9y ago> There is a dissertation in psychoanalytics just waiting to be written. Just don't wear a Hawaiian shirt while giving interview about it on TV.
- DINKDINK 9y agoGuess my password is safe, it seems it was skipped in the list: hunter1 - 3 times * * * * * * * - 28 times hunter3 - 2 times /s
- u801e 9y agoWhat would be nice is if we could improve the process of generating per device client side certificates that can be associated with a user account. Then we could just use certificate based authentication (and add on password based authentication if we want a second authentication factor).
- valtism 9y agohttps://mostsecure.pw/ https://mostsecure.pw/ No pwnage found. Still confirmed for most secure password.
- chuckdries 9y ago...this is a joke, right?
- deleted 9y ago[deleted]
- jrochkind1 9y ago> However, I got a lot of feedback from V1 along the lines of "simply blocking 320M passwords is a usability nightmare". Blocking half a billion, even more so. What, why?
- azinman2 9y agoBecause normal humans will only be able to generate so many passwords on their own before they give up. He also later makes the example of understanding the frequency matters — abc123 is mathematically equivalently bad to mno678, except one is far more likely than the other.
- eof 9y agoThis is a tangent; but I had a 'pwned' password that I've used for years on steam that started getting hacked like 4-5x a week; I would just ignore the 2 factor attempts for several months. I finally changed the password to a slight variation that is not in this list (nor likely any others, 9 random alphanumerics); and within a week the two factor notifications started back up! I was really surprised; admittedly the modification was trivial, but that is pretty thorough for a steam account I've spent like $100 in.
- stordoff 9y agoDid you have any items in the account (TF2, DOTA2 etc.)? Some of them sell for silly prices (and it isn't always immediately obvious which), which can result in your account being targeted.
- 6t6t6t6 9y ago"Write your password in this input field to see if it has been pwned" Me: ¬_¬
- dansingerman 9y agoThis is so useful I've knocked up a quick gem to wrap the range service (i.e. it only transmits the first 5 chars of the SHA1 hash) https://github.com/dansingerman/pwned_passwords_v2 https://github.com/dansingerman/pwned_passwords_v2 The code is left deliberately simple so eyeballing lets you know it's not doing anything hinky with the passwords.
- odammit 9y agoSplit brain your password storage. Another table, another database or another storage system in general. If an attacker SQL injections your database don’t go spilling every hashed or unhashed password you’ve got. I tend to store passwords in a separate keyvalue store from where my authentication identifier is (email, “username”). If someone gets into my network they need to get into my servers with the email addresses and then get into a secondary system where the passwords are stored. I like my password systems to be a k/v store because there is no need to “query” it. I usually store the password under a key that isnt the identifier. Instead using something like a database surrogate key. Have a secondary system (microservice, private subnet) that simply returns a boolean representing if the provided non-email (key) and password (value) match. Have that secondary system take the plain text password so it can do the hashing without letting the dependent service know what algorithm, salt or stretches you’re doing. This will also allow you to easily roll over to new hashing algorithms over time without affecting the service that is doing th authenticating. Edit: I’m not trying to be a know it all or a crabby old tinfoil hat a-hole. But it’s passwords, man. When you leak them you ruin people’s days/year/life. Building that system above takes a middle of the road engineer a day or two. Put the effort in. Every password leak makes all of our jobs harder. It’s your companies responsibility to keep that safe. If you know that already, be the annoying guy that brings it up in every stand up. Make that debt known.
- professorTuring 9y agoRule n1: don't roll your own security. Rule n2: goto 1 You are overcomplicating your authentication system by oversimplifying security problems and the result is that you have solved nothing. Security always seems very easy to solve and usually non-security engineers tends towards solutions like yours that doesn't provide extra security, they just add a few extra steps for a hacker to obtain you database and as a result you need to maintain extra databases, there are more error points... Do you remember that thing about "each extra system exponentiates complexity"?
- odammit 9y agoYou don’t have to “roll your own security.” You can easily put any open source security system behind a secondary system. Hell - it would already be a secondary system. Not putting your passwords right next to the identifiers is a simple way to lower the impact of an email or password leak. Also, that quote is bullshit.
- tazard 9y agoI feel like this could come in handy while looking for a date at https://wordsofheart.com/ https://wordsofheart.com/
- StapleHorse 9y agotroyhunt - 9 times Most secure name for a password possible. :D
- StapleHorse 9y agof--cktrump - 1 f--ckbush - 945 f--ckclinton - 0 f--ckobama - 128 I guess you can draw some conclusions there... maybe - pwned accounts were created between 2000-2016 - Democrats do worse at secure passwords? - In 2000-2008 people chosed worse passwords?
- dandare 9y agoAm I the only one here who thinks typing your password to a stranger's website is a risk? How do you know he does not log it? how do you know he was not hacked and someone is not logging all passwords that are not on the list YET.
- maze-le 9y agoIf you don't trust troy hunt / haveibeenpwned.com you can always download the data and analyze your password yourself. But if this is the case you should not trust any website with your password anwhere ever, and should not create accounts anywhere. Troy Hunt has shown himself a responsible security professional, and I trust him more to create a secure password query than some other security organizations.
- londons_explore 9y agoNo, you shouldn't trust this site with your password, like you shouldn't trust any site with your password. Choose a new password for every site folks, and if you want to use a site like this, make sure the original places you used the password have been updated to a new one.
- ajro 9y ago"But if this is the case you should not trust any website with your password anwhere ever". That is why you should use unique password for each site.
- maze-le 9y agoYes, with unique passwords for each services, you narrow the attack surface to compromise other accounts. But you still have to trust the operator to store and process this one - unique - password on this one service/website. It does not make any difference for the argument, if one or many accounts are potentially compromised. And you have to trust your password-manager software, since it is next to impossible to remember all the different passwords for all the different services you use.
- 9y ago
- tanu057 9y agowe have more love than hate. Good to see that in secret passowrds. iloveyou - 1,462,146 iloveu - 179,992 ihateyou - 58,656
- JimWestergren 9y agoThis is really great and I will use this API. Wrote a simple method in PHP using 10 lines: https://gist.github.com/JimWestergren/a4baf4716bfad6da989417a10e1ccc5f https://gist.github.com/JimWestergren/a4baf4716bfad6da989417... Feel free to use.
- capex 9y agousername 8340
- eni 9y agoHow trustworthy is /haveibeenpwned.com? Is there a chance the password people enter there for checking will end up in the databases?
- jrgv 9y agoThe article explains how the site has been designed not to send passwords to the server. Of course, it's up to you to decide if you trust them to keep it that way.
- maaark 9y agoThere is almost zero chance Troy Hunt would torpedo his carreer doing something as monumentally stupid as that. It's possible, sure. But I'd trust him with my password sooner than I'd trust [INSERT SV COMPANY HERE].
- caf 9y agoMight be fun to create a PAM module that warns you when you login if your password is in the list.
- brwsr 9y agoIt would be great if the many password managers out there like keepass for example, use this data to filter out any password that exists in the list. I know it would be very rare, but still, why not filter them out?
- grinsekatze 9y agoWhat would be the point of filtering out passwords that are in the list, when using keepassX or other password managers? Isn't the point of password manager that you don't have to choose or come up with passwords yourself?
- iask 9y agoWouldn’t reversing each password (reading right to left) produce a new list of “Half a Billion” passwords to use?
- jakobegger 9y agoI love that simple API! Here's a bash one-liner that checks if 'hello' is compromised: curl -s https://api.pwnedpasswords.com/range/$(echo https://api.pwnedpasswords.com/range/$(echo -n hello | shasum | cut -b 1-5) | grep $(echo -n hello | shasum | cut -b 6-40 | tr /a-f/ /A-F/) Edit: Improved one-liner that only requires typing the password once and avoids storing it in the bash history: (echo -n "Password: "; read pw; curl -s https://api.pwnedpasswords.com/range/$(echo https://api.pwnedpasswords.com/range/$(echo -n $pw | shasum | cut -b 1-5) | grep $(echo -n $pw | shasum | cut -b 6-40 | tr /a-f/ /A-F/))
- espadrine 9y agoYou can use `read -s` to avoid risking having someone behind you read your password on your screen as you type it. (echo -n "Password: "; read -s pw; curl -s https://api.pwnedpasswords.com/range/$(echo https://api.pwnedpasswords.com/range/$(echo -n $pw | shasum | cut -b 1-5) | grep $(echo -n $pw | shasum | cut -b 6-40 | tr a-f A-F))
- NoGravitas 9y agoswordfish: 74,878 times I guess the password is always "swordfish".
- CurtMonash 9y agoThere's something odd about a website that urges you to test your security by typing in your password.
- smoyer 9y agoHe specifically tells you that you shouldn't do that. But as the winning tool shows, perhaps people who have passwords in HIBP will changed them after finding this out?
- pcunite 9y agoIs there a large file dump of plaintext passwords out there?
- dom96 9y agoIn case anyone here is interested, I just did a livestream where I wrote a simple app in Nim to query this API. On YouTube: https://www.youtube.com/watch?v=Di2O_lIPxb4 https://www.youtube.com/watch?v=Di2O_lIPxb4 Source code: https://github.com/dom96/pwned https://github.com/dom96/pwned