3 ms·
If that happens commonly, the original password with a 1 appended will probably eventually appear in a future HIBP database. In fact, the user could continue ad
by mnutt 8y ago
If that happens commonly, the original password with a 1 appended will probably eventually appear in a future HIBP database. In fact, the user could continue adding 1s until they either give up and try something different, or until it becomes uncommon enough.
- MarkMc 8y agoHere's an example of that user experience: User: Set my password to 'monkey' Website: Sorry that's a common password User: OK, set my password to 'monkey1' Website: Sorry that's a common password User: What?! OK, set my password to 'monkey123' Website: Sorry that's a common password User: Grr! Set my password to 'monkey123fuckyou!!' Website: Sorry that's a common password User: Screw this, I'll just sign up to your competitor's website instead
- tialaramex 8y agoBut with Pwned Passwords after that last attempt it just works. Because your scenario is imaginary and you haven't actually checked these were all backlisted. Whether the user will remember they picked "monkey123fuckyou!!" is a good question, but it's a markedly better password than "monkey".
- mnutt 8y agoThat doesn’t seem too far off from what I would expect, if your site actually cares about the data your users store there. I wouldn’t recommend it, but you could try a slightly scarier explanation. (“Sorry, hackers have cracked this password on other sites. If you use this password elsewhere, you should consider immediately changing it.”)