Password check via haveibeenpwned

WoodiE

Well-known member
It would be great if there was an add-on for our forums that checked the users password during account creation and password change, against known breached passwords (checked against haveibeenpwned.com) and then suggests using something stronger.

A website https://toepoke.co.uk/user.aspx/create does this now using the above suggestion:pwned-password.webp


Just something to keep our forums and users a bit more secure.
 
Thanks @ozzy47, I'll reach out to @DragonByte Tech and double check as there is nothing in that resource that I seen that specifically mentions checking passwords on creations/reset for known breached passwords from haveibeenpwned or any other service.
 
Thanks @ozzy47, I'll reach out to @DragonByte Tech and double check as there is nothing in that resource that I seen that specifically mentions checking passwords on creations/reset for known breached passwords from haveibeenpwned or any other service.
DB Security will execute a check against HIBP upon failed login. You can also manually run a check via the AdminCP :)


Fillip
 
So after PM'ing DragonByte I can confirm this addon does NOT do what I'm seeking. His addon only checks HIBP during a failed login.

I'm looking for something that will check a users password when a new user is registering or when an existing member is changing their password.
 
XF Error phrases hate on HTML, so I haven't yet figured out how to add a link telling the user what to-do.
 
Oh ok, cool.. I assumed since it was a Feb 2018 request, it was a request for 2.x+!

Look forward to it should that happen!
 
Oh ok, cool.. I assumed since it was a Feb 2018 request, it was a request for 2.x+!

Look forward to it should that happen!
I bet if a few bucks was thrown toward @Xon's general direction he'd probably be able to speed up the XF 2.0 version. ;)
 
  • Like
Reactions: Xon
Top Bottom