11 ms·
I don't think this is a significant advantage, the cost of an incorrect password attempt is essentially zero. Trying "every password they have on every website"
by bbbbb5 4y ago
I don't think this is a significant advantage, the cost of an incorrect password attempt is essentially zero. Trying "every password they have on every website" for an individual will still be a very small set of passwords to try.
- Shaanie 4y agoI could see password reuse being used as a reason for trying brute force/dictionary attacks. E.g. You see that a user has used the same password on Coinbase as X, which could indicate that the user isn't using randomly generated passwords and therefore be potentially vulnerable to such attacks. Kind of a long shot though.
- cmeacham98 4y agoAttackers generally aren't targeting a specific individual, they got a dump of X million passwords from some compromised website. Being able to connect those directly to working accounts rather than having to burn IPs and get them rate limited and/or banned trying duds _is_ valuable information. If you have some attacker after specifically you, yes this information is of less use to them, because they will have tried every password of yours they have on every website already hoping you reuse passwords.