Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.


BDFL - Memuneh
61024 posts

Uber Geek
+1 received by user: 11853

Administrator
Trusted
Geekzone
Lifetime subscriber

Topic # 237519 5-Jun-2018 21:54
7 people support this post
Send private message quote this post

I am thinking of adding a small piece of logic that will test your password at login, using the http://haveibeenpwned.com/ API to determine if the password you use to login on Geekzone has been compromised in another site - reusing passwords is quite normal and people don't think much about it.

 

My question is - how do think a message like "The password you use on Geekzone has been previously used by yourself or someone else on another site. This password has been leaked as per http://haveibeenpwned.com/. We suggest you change your password on Geekzone and other sites. Make sure to create unique passwords for each service you use."

 

Do you think this is clear enough so that most people understand a compromised password wasn't leaked by Geekzone, but some other service? Suggestions?

 

To be clear, testing via their API never sends a password but only a hash of it. We'd do this check at login time because that's the time our scripts have your password - we salt and hash the password before it's stored in our database so we wouldn't know it.





View this topic in a long page with up to 500 replies per page Create new topic
 1 | 2
303 posts

Ultimate Geek
+1 received by user: 57

Subscriber

  Reply # 2030371 5-Jun-2018 21:57
Send private message quote this post

Good idea, suggest you do this





gml


2475 posts

Uber Geek
+1 received by user: 674


  Reply # 2030373 5-Jun-2018 22:05
Send private message quote this post

So the test page says I’ve been compromised... is this a legit test of my password, or a test of the ‘compromised’ message 🤔

mdf

1860 posts

Uber Geek
+1 received by user: 538

Trusted
Subscriber

  Reply # 2030378 5-Jun-2018 22:09
3 people support this post
Send private message quote this post

+1 great idea. You're speaking to a relatively tech savvy audience (I hope?). The short message is good (perhaps with some bolding or caps "The password you use on Geekzone has been previously used by you or someone else on another site that has been compromised"), but I'd put a link to a longer explanation as to how we test (i.e. we didn't send your password in the clear to anyone) and how to pick a good password (cough, link to a password manager).




BDFL - Memuneh
61024 posts

Uber Geek
+1 received by user: 11853

Administrator
Trusted
Geekzone
Lifetime subscriber

  Reply # 2030380 5-Jun-2018 22:12
Send private message quote this post

PhantomNVD: So the test page says I’ve been compromised... is this a legit test of my password, or a test of the ‘compromised’ message 🤔


Did you put your own password there? If so, then yes. That page is not testing your actual password as we don't know it.






BDFL - Memuneh
61024 posts

Uber Geek
+1 received by user: 11853

Administrator
Trusted
Geekzone
Lifetime subscriber

  Reply # 2030384 5-Jun-2018 22:20
2 people support this post
Send private message quote this post

@PhantomNVD: So the test page says I’ve been compromised... is this a legit test of my password, or a test of the ‘compromised’ message 🤔

 

Let me clarify... The test page linked here is just a demo and uses the password you pass as a parameter in the URL. We don't know your password because it's hashed in our database. The idea is to put this same code in the login script and automatically let you know of something "strange" with your password. The demo is just for me to know the code works (and for you to play with)

 

How it works?

 

https://haveibeenpwned.com/ has a list of emails that leaked over the years from different services. Visit the site and enter your email address. It will tell you where it leaked and I strongly suggest you change your password on any of those services listed.

 

They also offer a password lookup service. You can enter a password and it will tell you if it's been compromised.

 

Now, it may be YOUR password. Or may be other people used the same password as you. For example "password", "god" are very common passwords so of course they will show as compromised. "IhaveaRedHorsethatannoy$inWellington" is not a common password - it's not compromised but that's not to say someone haven't used it.

 

A lot of people reuse their passwords in different services. This is bad because if one service leaks the password some Bad Guy (TM) can just use your email/password and go around trying to login - let's say they find your email and password on a Dial-a-Pizza service and then try on your Bank of My Country. And you used the same password in both. You're done.

 

So this service won't say YOUR password leaked. It will tell you that YOUR password or someone else's password that is exactly the same as yours, leaked. You then should go to the https://haveibeenpwned.com/ and check if your email is part of a leak.

 

In either case if your password is shown as compromised you should change it for something safer and unique.

 

Makes sense?







BDFL - Memuneh
61024 posts

Uber Geek
+1 received by user: 11853

Administrator
Trusted
Geekzone
Lifetime subscriber

  Reply # 2030386 5-Jun-2018 22:26
3 people support this post
Send private message quote this post
3373 posts

Uber Geek
+1 received by user: 1874

Trusted
Lifetime subscriber

  Reply # 2030389 5-Jun-2018 22:34
Send private message quote this post

This is great tested mine and all good

 

Password ok 200

 

John





Ex JohnR VodafoneNZ 17 years 4 days

Go Hawks!
876 posts

Ultimate Geek
+1 received by user: 49

Trusted
Subscriber

  Reply # 2030404 5-Jun-2018 23:17
One person supports this post
Send private message quote this post

freitasm:

 

Funny thing is someone used "Trump" as a password...

 

 

I believe you've just leaked the President of the US of A's password ... oops!

 

 


666 posts

Ultimate Geek
+1 received by user: 277

Subscriber

  Reply # 2030448 6-Jun-2018 07:26
One person supports this post
Send private message quote this post

freitasm:

 

or someone else's password that is exactly the same as yours, leaked.

 

 

I'm more concerned about my email address and password pair being compromised, can you query for a match on both?

 

 










BDFL - Memuneh
61024 posts

Uber Geek
+1 received by user: 11853

Administrator
Trusted
Geekzone
Lifetime subscriber

  Reply # 2030449 6-Jun-2018 07:28
Send private message quote this post
2333 posts

Uber Geek
+1 received by user: 918

Lifetime subscriber

  Reply # 2030488 6-Jun-2018 08:55
Send private message quote this post

The "haveibeenpwned" website says that I have been!

 

But when I look it gives a set of websites that have been exploited and the dates... and my passwords are all much newer than that and are machine generated gobbledygook - does that mean I'm ok?

 

 

 

 


2333 posts

Uber Geek
+1 received by user: 918

Lifetime subscriber

  Reply # 2030491 6-Jun-2018 08:59
Send private message quote this post

freitasm:

 

Funny thing is someone used "Trump" as a password...

 

 

It says "compromised" if you put any actual words or names in there such as "alphabet" or "mauricio" ... does dictionary existence automatically give a "compromised"?

 

 


1567 posts

Uber Geek
+1 received by user: 152

Trusted

  Reply # 2030495 6-Jun-2018 09:12
Send private message quote this post

Suggest you kill all sessions (we've had it happen a few times in recent weeks,what is once more) once this is implemented to clean the database.

 

Better yet do not let people use these passwords at all, they have to keep trying until its not in the database.

 

Maybe also include a link to password safes (keepass etc) to help people do better





CPU: Intel 3770k| RAM: F3-2400C10D-16GTX G.Skill Trident X |MB:  Gigabyte Z77X-UD5H-WB | GFX: GV-N660OC-2GD gv-n660oc-2gd GeForce GTX 660 | Monitor: Qnix 27" 2560x1440

 

 


4975 posts

Uber Geek
+1 received by user: 1587


  Reply # 2030501 6-Jun-2018 09:24
One person supports this post
Send private message quote this post

mentalinc: [snip]

 

Better yet do not let people use these passwords at all, they have to keep trying until its not in the database.

 

 

If I understand correctly though, this is a database of basically any password that any person has used, so people are being asked to have a password that is globally unique to any account from any person - that's a pretty tall order.

 

 


2333 posts

Uber Geek
+1 received by user: 918

Lifetime subscriber

  Reply # 2030510 6-Jun-2018 09:37
2 people support this post
Send private message quote this post

RunningMan:

 

mentalinc: [snip]

 

Better yet do not let people use these passwords at all, they have to keep trying until its not in the database.

 

 

If I understand correctly though, this is a database of basically any password that any person has used, so people are being asked to have a password that is globally unique to any account from any person - that's a pretty tall order.

 

 

Easy to do if you use a machine generated random password. However as these are basically impossible to remember it means you'll need to either write them down (insecure) or use a password manager such as LastPass, which is potentially a catastrophic vulnerability if it is broken into.

 

I use LastPass... I am on so many systems it's impossible not to without sharing passwords between them.

 

 

 

 


 1 | 2
View this topic in a long page with up to 500 replies per page Create new topic

Twitter »

Follow us to receive Twitter updates when new discussions are posted in our forums:



Follow us to receive Twitter updates when news items and blogs are posted in our frontpage:



Follow us to receive Twitter updates when tech item prices are listed in our price comparison site:





News »

Intel introduces new NUC kits and NUC mini PCs
Posted 16-Aug-2018 11:03


The Warehouse leaps into the AI future with Google
Posted 15-Aug-2018 17:56


Targus set sights on enterprise and consumer growth in New Zealand
Posted 13-Aug-2018 13:47


Huawei to distribute nova 3i in New Zealand
Posted 9-Aug-2018 16:23


Home robot Vector to be available in New Zealand stores
Posted 9-Aug-2018 14:47


Panasonic announces new 2018 OLED TV line up
Posted 7-Aug-2018 16:38


Kordia completes first live 4K TV broadcast
Posted 1-Aug-2018 13:00


Schools get safer and smarter internet with Managed Network Upgrade
Posted 30-Jul-2018 20:01


DNC wants a safer .nz in the coming year
Posted 26-Jul-2018 16:08


Auldhouse becomes an AWS Authorised Training Delivery Partner in New Zealand
Posted 26-Jul-2018 15:55


Rakuten Kobo launches Kobo Clara HD entry level reader
Posted 26-Jul-2018 15:44


Kiwi team reaches semi-finals at the Microsoft Imagine Cup
Posted 26-Jul-2018 15:38


KidsCan App to Help Kiwi Children in Need
Posted 26-Jul-2018 15:32


FUJIFILM announces new high-performance lenses
Posted 24-Jul-2018 14:57


New FUJIFILM XF10 introduces square mode for Instagram sharing
Posted 24-Jul-2018 14:44



Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.



Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.

Alternatively, you can receive a daily email with Geekzone updates.