4 ms·
Editing since I misunderstood you: If you publish one trillion passwords from a large space then each one of them gets a probability boost (of approximately 1/
by rmtech 8y ago
Editing since I misunderstood you:
If you publish one trillion passwords from a large space then each one of them gets a probability boost (of approximately 1/1 trillion), though not enough to ban them, especially if they are not actually associated with accounts.
The danger with using a rare but breached password is that there is actually quite a high chance that it was breached from your account elsewhere.
- geofft 8y agoI think we're reading the question differently - I'm responding to the question of, what if you publish a tiny subset of the passwords, 20 trillion out of 0.7 trillion trillion trillion. That does change the probabilities. I do agree that if the entire space of possible passwords is only 20 trillion, that doesn't change the probabilities. But there are over 20 trillion eight-character alphanumeric passwords. So, I would actually say you should ban them all, because you should insist your passwords are at least eight characters long. :-) Edit: yes, agree, in practice the probability boost is not very much. I'm just saying you may as well ban them on the assumption that the HIBP API will do so at its current level of performance. (20 trillion is a ridiculous number, because it's much larger than any possible breach and yet much smaller than any meaningful password space, so any arguments about it are going to be inherently silly in some fashion. My current silly assumption is that the HIBP API is capable of ingesting 20 trillion breached passwords with no performance hit.)
- rmtech 8y agoWell there is one important factor about these 20 trillion passwords: are they associated with real user accounts? If not then it really doesn't matter that they got published. They're useless to hackers without knowing what email to type in. The attack model is that the attacker actually has to log into a website and you don't get 20 trillion attempts.
- Dylan16807 8y agoNever underestimate the ingenuity of the user. They might search for a list of good passwords, find it, and pick one. > The attack model is that the attacker actually has to log into a website Not to find the password. If it was then nobody would get upset about plaintext password storage.
- geofft 8y agoRight - "attacker gets an old database backup, and wants to escalate to access to the live website" (or perhaps "attacker breaches QA", or something) is a realistic attack model. Take all the known passwords, hash them, match the hashes against the database, look at the next column over to see whose accounts you compromised.
- rmtech 8y agoWell if we're talking about the possibility of an offline attack against a password database that's a bit different. The standards for a good password are higher for that attack. But anyway if you pick a password from a list of 20 trillion where the offline attacker knows the list, it doesn't actually help them much because a single selection from 20 trillion options has 44 bits of entropy. Passwords that users choose typically have less entropy than that afaik
- Dylan16807 8y agoMost passwords are worse, yeah, but 44 bits isn't great. With a fast hash that's less than a GPU-week. It's basically enough if you use bcrypt, but even then it's not protected from an attacker with a lot of money to throw at it. (8 GPUs per server, 10 servers per rack, 50 racks, suddenly you're hashing work-factor-10 bcrypt passwords at about 2 million per second and average cracking time is 50 days.)