3 ms·
If you're looking to build a server-side check for password re-use, I'd suggest using the Have I Been Pwned API. When searching by range[0], you only send the f
by conroy 8y ago
If you're looking to build a server-side check for password re-use, I'd suggest using the Have I Been Pwned API. When searching by range[0], you only send the first 5 characters of the SHA-1 password hash, thus preserving the privacy of your users' passwords. Cloudflare has a great write up on how it works[1].
[0] https://haveibeenpwned.com/API/v2#SearchingPwnedPasswordsByRange https://haveibeenpwned.com/API/v2#SearchingPwnedPasswordsByR...
[1] https://blog.cloudflare.com/validating-leaked-passwords-with-k-anonymity/ https://blog.cloudflare.com/validating-leaked-passwords-with...