4 ms·
* Phase 1: Setup password checking site pretending to check passwords against stolen passwords. Steal all passwords inputted. * Phase 2: ??? * Phase 3: Profit
by SlowBro 9y ago
* Phase 1: Setup password checking site pretending to check passwords against stolen passwords. Steal all passwords inputted.
* Phase 2: ???
* Phase 3: Profit
(Downvoters, I'm only having fun, and yes I know this is a good source. But: Do be vigilant. It doesn't take a stretch of the imagination to suppose that this scenario could happen.)
- xigency 9y agoThe HIBP password check API uses k-anonymity so it is secure-ish to use. It's shown here under "How It Works."
- zie 9y agoFor sure, this is possible. But Troy Hunt is well known, and using his new v2 API, at most only 5 characters of the sha1 hash is sent across. Alternatively, like I did, you can download the 31GB file and do it all locally, and not involve network round trips. 1p is well known in the community for being pretty good with security, so the chances of them implementing this in a different way than they say they did would be severely damaging to their reputation. Once it comes out in local 1p apps, we can verify that they did do it the way they said they did.
- SlowBro 9y agoI'm only having fun but yes, I am sure it's a solid source. I have in fact inputted one of my weaker (common, low-impact forum-only) passwords there in the past. It was pwned.
- zaroth 9y ago5 characters of hex is 20 bits, meaning only about 1 in a million passwords will match the prefix, right? So you are giving someone a way to eliminate 99.9999% of their candidates for your password with that hash prefix.
- ReverseCold 9y agoThat's only if your password is weak. If no one's ever seen it before (generated by password manager) it wouldn't really help much.
- zaroth 9y agoThe resolution of the discriminator has nothing to do with the strength of your password. Having the first 20 bits of the hash certainly isn’t the same as having the whole thing, but the simple math says that only 1 in a million wrong guesses will match. This is very powerful, for example, if you have a strong hash which you want to crack along with the first 5 characters of the SHA1 because then you only have to run the slow hash 1 in a million times. It’s also very powerful if you want to do an online attack because you can narrow down your guesses quite significantly. Lastly, if you are logging in with keys (random entropy encoded as human readable string) rather than passwords of course none of this concerns you in the slightest, nor do you have any use for this API in the slightest. To state it another way, if you have 80 bits of entropy in your password, maybe no big deal to throw away 20 bits worth (but for what purpose?). However the average password has less than 30 bits of entropy, so throwing away 20 bits is a big deal. The end result is there’s a lot of trust being placed in this API, and in particular the idea that services should be calling out to it as part of a login process, or that we should be training average users to test their passwords in a webform, that is concerning.
- zie 9y agosqlite> select substr(hash,1, 5) as hashbeg, count(*) as count from pwned group by hashbeg; # put result into hashcount table sqlite> select avg(count) from hashcount; 478.397716142925 sqlite> select min(count) from hashcount; 381 So, I'm not sure I agree with you, if on avg almost 500 records are returned given the first 5 chars of the SHA1 hash across the 1/2 billion records. But I do agree it helps with cracking the passwords, but seeing as how all of these passwords are BAD and are known to have leaked... cracking them again isn't the use-case, the bad people likely already have all these passwords in plain text.
- 9y ago