5 ms·
I wrote this small python function to check if a password is part of a breach by transmitting only the first 5 digits of it's hash: https://gist.github.com/mcda
by sethgecko 8y ago
I wrote this small python function to check if a password is part of a breach by transmitting only the first 5 digits of it's hash: https://gist.github.com/mcdallas/d94ecd8b34a6bf57a162a7af0ce2a664 https://gist.github.com/mcdallas/d94ecd8b34a6bf57a162a7af0ce...
- rahimnathwani 8y agoYour code uses the first 5 digits of the hex digest of the SHA1. This 5-digit hex number has roughly 1 million combinations. That seems way too low. For context: If you take just dictionary words from the world's 5 most popular languages, you'd have more than 0.5 million words.
- sethgecko 8y agoThis is from the API docs, you are not allowed to pick the number of digits. https://haveibeenpwned.com/API/v2#SearchingPwnedPasswordsByRange https://haveibeenpwned.com/API/v2#SearchingPwnedPasswordsByR...
- rahimnathwani 8y agoOh I see, so you send only the first 5 digits, but you then get back ~16,730 digits (478 * (40-5)) and search those for your full hash.
- qop 8y agoSo what if you then took positives from 5dig hash matches and searched then through 7dig hash matches? Like a sieve? With a good cache, thatd save some bandwidth. Maybe that's wishful thinking. I can't imagine checking new passwords more than a few dozen times per second at the most. Bigger sites probably just write their own password integrity tools.
- mrybczyn 8y agoI applaud your optimism! Most places just enforce byzantine password requirements, 13 digits, must have ~, uppercase and a palindrome prime integer in it. Obligatory password XKCD, think of the children. https://xkcd.com/936/ https://xkcd.com/936/
- qop 8y agoI can imagine if there was a more standard password definition, eventually specialized hardware would adapt to whatever the standard was, in terms of cracking attacks. I use a memory trick to have very strong passwords, but most people probably wouldn't be willing to invest the effort. Someday there will be a better way.
- programbreeding 8y agoFYI: "Due to the massive popularity of the range search over searching by complete password hash, the significantly improved performance and the enhanced privacy controls, searching by hash will be discontinued on 1 June 2018." Shown in API docs under "Pwned Passwords overview" and links to here: https://www.troyhunt.com/enhancing-pwned-passwords-privacy-by-exclusively-supporting-anonymity/ https://www.troyhunt.com/enhancing-pwned-passwords-privacy-b...
- rahimnathwani 8y agoI can't tell whether you knew this from the way your post is written, but this refers to searching by complete hash, not searching by the first 5 digits (aka range search).
- sethgecko 8y agoI think what he means is that searching by full hash will be removed in favour of using the /range endpoint (the one I am using)
- Freaky 8y agoI wrote a Rust tool to process the downloaded hash list into a compact (29GB -> 1.5GB) database that can be efficiently queried: https://github.com/Freaky/gcstool https://github.com/Freaky/gcstool I made a start on a Ruby port too: https://github.com/Freaky/ruby-gcs https://github.com/Freaky/ruby-gcs - I have vague plans to finish it off and write a Rodauth (http://rodauth.jeremyevans.net/ http://rodauth.jeremyevans.net/) plugin for it.
- michaelbanfield 8y agoAdding the the plug train :) I wrote a devise extension thats essentially a one liner to add this check on signup (and a small code block to add on signin) https://github.com/michaelbanfield/devise-pwned_password https://github.com/michaelbanfield/devise-pwned_password Nowadays most of the logic is encapsulated in the pwned gem https://github.com/philnash/pwned https://github.com/philnash/pwned Which is a good choice if you arent using devise.