Reply to thread

Troy has a new dataset - completely separate from the HIBP system.


See here: https://www.troyhunt.com/introducing-306-million-freely-downloadable-pwned-passwords/


His original HIBP system just lets you check email addresses against breaches (no password matching), while this new (separate) system lets you check a password against a set of previously hacked passwords (no account matching) to make recommendations about password strength based on NIST recommendations about checking against "passwords obtained from previous breach corpuses".


He is not cross referencing account signons with passwords or anything like that - there is no matching occurring, it's simply a dictionary of previously hacked passwords.


Back
Top Bottom