4 ms·
> If the password actually has a lot of entropy but it appears in a breach then that's some fairly strong evidence that the user is reusing it. I'm not talking
by throwawaymath 8y ago
> If the password actually has a lot of entropy but it appears in a breach then that's some fairly strong evidence that the user is reusing it.
I'm not talking about scenarios where you can associate the password with a specific user.
- greglindahl 8y agoMany people use the known passwords list with offline cracking tools.
- rmtech 8y agowell when the password got breached it is associated with a particular user. And HIBP will tell you how many times a given password appears, but not which account it appears with. See: https://haveibeenpwned.com/Passwords https://haveibeenpwned.com/Passwords
- geofft 8y agoYou can in fact associate the password with a specific user - the fact that that exact password is being reused is, by itself, strong mathematical evidence that it's the same user or someone they told the password to, because it is basically mathematically impossible that anyone else could generate the same password by coincidence (unless they're both using a password generator that doesn't have good random seeds or is otherwise deterministic, in which case you should be banning the password anyway).
- rmtech 8y ago> exact password is being reused is, by itself, strong mathematical evidence that it's the same user yes, exactly.
- geofft 8y agoI thought of another way of putting this - a 20-character alphanumeric password is a random 114-bit value. A UUIDv4 is a random 122-bit value (the remaining bits are specified by the UUID spec). If you generate UUIDs for your users, and you don't expect two users to end up with the same UUID, it would be confusing if you somehow expected two users with 20-character alphanumeric passwords to potentially collide. The probabilities are just a factor of 256 from each other.
- Dylan16807 8y ago(119 not 114, there are 62 alphanumerics)