New tool safely checks your passwords against a half-billion pwned passwords

Discussion in 'other security issues & news' started by hawki, Feb 23, 2018.

  1. EASTER

    EASTER Registered Member

    Joined:
    Jul 28, 2007
    Posts:
    11,126
    Location:
    U.S.A. (South)
    Funny coincidence you should mention that. Same thing.

    My ISP throttles from roughly 5 PM EST until Midnight. Horrid service reaches it's worse at 10PM EST.

    On downloads I see 4-10 Kb-s which is useless. The D/L's always give up the ghost and time out after some seconds/minutes.

    Most peeps are snugged in bed after midnight. Grrrr. I aim to drive over to them and ask why im not getting the terms agreed to during that period. UGH
     
  2. Reality

    Reality Registered Member

    Joined:
    Aug 25, 2013
    Posts:
    1,198
    I was thinking of ordinary users who don't necessarily use VPN or other measures to obscure ip. I think I'll take on your minimalist namesake here :). Less is definitely more.
     
  3. Reality

    Reality Registered Member

    Joined:
    Aug 25, 2013
    Posts:
    1,198
    Mine is patchy like this as well. It's a royal pain. I plan to get onto them about it as well - fully expecting the passing of the buck.
     
  4. RockLobster

    RockLobster Registered Member

    Joined:
    Nov 8, 2007
    Posts:
    1,812
    Yes I thought that too so I only checked a few old passwords I no longer use.
     
  5. XIII

    XIII Registered Member

    Joined:
    Jan 12, 2009
    Posts:
    1,383
    That's encrypted with 7-Zip.

    The actual file is 31.6 GB...
     
  6. EASTER

    EASTER Registered Member

    Joined:
    Jul 28, 2007
    Posts:
    11,126
    Location:
    U.S.A. (South)
    Hah ha. No wonder. I started the download but the ETA was way too off the charts for what feeble bandwidth is distributed to my section of the masses.

    Sure though however I could pull that whole base at a library where speeds are infinitely better than my own services.

    It is IMO worth the extra trip and effort.
     
  7. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,883
    Location:
    Slovenia, EU
    https://www.troyhunt.com/i-wanna-go-fast-why-searching-through-500m-pwned-passwords-is-so-quick/
     
  8. Krusty

    Krusty Registered Member

    Joined:
    Feb 3, 2012
    Posts:
    10,240
    Location:
    Among the gum trees
    2 passwords I tried were OK, but if you use randomly generated longish passwords and different passwords for each site you shouln't have too much to worry about, right?
     
  9. RockLobster

    RockLobster Registered Member

    Joined:
    Nov 8, 2007
    Posts:
    1,812
    Yes that and the good thing about generated passwords its easy to change them regularly.
     
  10. guest

    guest Guest

    Okta’s PassProtect checks your passwords with ‘Have I Been Pwned’
    May 23, 2018
    https://techcrunch.com/2018/05/23/oktas-passprotect-checks-your-passwords-with-have-i-been-pwned/
    Related:
    Chrome plug-in tells you when hackers have your password
    And yes, it does have a system to avoid leaking your password itself.
    May 23, 2018
    https://www.cnet.com/news/chrome-plug-in-tells-when-hackers-have-your-password-okta/
     
  11. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
  12. guest

    guest Guest

    Spybot Identity Monitor
    Website
    Review:
    A look at Spybot Identity Monitor for Windows
    October 29, 2018
    https://www.ghacks.net/2018/10/29/a-look-at-spybot-identity-monitor-for-windows/
     
  13. guest

    guest Guest

    New monitoring tool checks the dark web for stolen credentials
    November 01, 2018
    https://betanews.com/2018/11/01/monitoring-dark-web-stolen-credentials/
    Introducing BreachWatch by Keeper
    https://keepersecurity.com/blog/2018/10/29/introducing-keeper-breachwatch/
     
  14. xxJackxx

    xxJackxx Registered Member

    Joined:
    Oct 23, 2008
    Posts:
    8,642
    Location:
    USA
    At what point does this list get long enough that using it would be no more effective than just guessing?
     
  15. 142395

    142395 Guest

    Assume each 10,000,000,000 users all have 1,000 diff pwds (none of them overlaps) and all of them are now included in the list. It's still less than 0.15% of 1-8 char pwds made from printable ASCII char.
    So, practically, the answer is "never".
     
  16. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.