6 ms·
If the password actually has a lot of entropy but it appears in a breach then that's some fairly strong evidence that the user is reusing it. Specifically if i
by rmtech 8y ago
If the password actually has a lot of entropy but it appears in a breach then that's some fairly strong evidence that the user is reusing it.
Specifically if it appears n times in the HIBP database you should assign at least roughly 1/n probability that the user is reusing it.
So if you assign disutility -V to letting a user have a known username + password combo and utility U to letting a user sign up with a known password but unknown username, the utility is (n-1)/n×U - 1/n×V
Reasonable values of U and V for a given site will be different depending on the application, but for online banking -V would be maybe -20 and U might be negative as well. You wanna bank with a public password lol? For something like gmail or Facebook it would be the same story.
On the other hand if the password is quite weak then it's vulnerable to credential stuffing. If it appears, say, 10,000 times in the HIBP database then most likely it's as good as public whether or not the user account name is known.
Maybe there's a sweet spot around 50 instances where you can't really credential stuff it, and you also aren't that sure that it's a reuse.
In terms of usability you could tell the user to change it up a bit, add some words.
For example, r0bbiewilliams appears 5 times in the database. luvrobbiewilliams appears 0 times AND IS PROBABLY EASIER TO REMEMBER!
You can almost always get away from a breached password by adding a small amount of text.
- throwawaymath 8y ago> If the password actually has a lot of entropy but it appears in a breach then that's some fairly strong evidence that the user is reusing it. I'm not talking about scenarios where you can associate the password with a specific user.
- greglindahl 8y agoMany people use the known passwords list with offline cracking tools.
- rmtech 8y agowell when the password got breached it is associated with a particular user. And HIBP will tell you how many times a given password appears, but not which account it appears with. See: https://haveibeenpwned.com/Passwords https://haveibeenpwned.com/Passwords
- geofft 8y agoYou can in fact associate the password with a specific user - the fact that that exact password is being reused is, by itself, strong mathematical evidence that it's the same user or someone they told the password to, because it is basically mathematically impossible that anyone else could generate the same password by coincidence (unless they're both using a password generator that doesn't have good random seeds or is otherwise deterministic, in which case you should be banning the password anyway).
- rmtech 8y ago> exact password is being reused is, by itself, strong mathematical evidence that it's the same user yes, exactly.
- geofft 8y agoI thought of another way of putting this - a 20-character alphanumeric password is a random 114-bit value. A UUIDv4 is a random 122-bit value (the remaining bits are specified by the UUID spec). If you generate UUIDs for your users, and you don't expect two users to end up with the same UUID, it would be confusing if you somehow expected two users with 20-character alphanumeric passwords to potentially collide. The probabilities are just a factor of 256 from each other.
- Dylan16807 8y ago(119 not 114, there are 62 alphanumerics)