4 ms·
I just tried 'passwordpassword' and it was there. You can download the whole dataset at the bottom of this page https://haveibeenpwned.com/Passwords https://ha
by michaelbanfield 8y ago
I just tried 'passwordpassword' and it was there. You can download the whole dataset at the bottom of this page
https://haveibeenpwned.com/Passwords https://haveibeenpwned.com/Passwords
Its a losing battle trying to add byzantine rules to prevent users doing things like using their normal password * 2, so its probably a reasonable check to add.
- mynameismonkey 8y agoAha, I tried a few obvious 16s but not that one... thank you! I guess we'll add it in. The last few dumps (other sources) I reviewed contained nothing over 15 characters, but I'm imagining they will start creeping in as more folks demand longer phrases. Still, I'd bet the vast majority of the bad passes are <16, seems a heck of a waste of energy and bandwidth to check my user's passphrases against (guesstimating) 0.05% of the corpus.