Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.


freitasm

BDFL - Memuneh
79250 posts

Uber Geek

Administrator
ID Verified
Trusted
Geekzone
Lifetime subscriber

#281202 4-Feb-2021 22:05
Send private message

Sometime soon I will deploy a new feature to our login page - we will automatically check for compromised passwords against the Have I Been Pwned database.

 

Users trying to login with passwords that are found to be compromised will not be allowed to login and will be redirected to a page explaining why with the option to initiate the reset password process. If your password has been compromised you will need access to your email to successfully reset it.

 

Important things to note:

 

- compromised passwords mean the password is the same as a password used in some other service that have been leaked. This affects people who re-use passwords and people who use common passwords 

 

- this doesn't mean our system was compromised - it only means the password was compromised somewhere else (and might even be that it's not your password that was compromised but only that you used a common enough password)

 

- this doesn't mean we know your password - it only means the password entered in the form will be checked during the login process, as received

 

- all sessions will be killed before this change goes live

 

- the API does not require your whole password to be sent. The short explanation is that we hash the password as entered in the form and send only the five first digits of the hash, with the API responding with a list of other digits that we can then compare to our entire hash. The API is described here.   

 

If you want to be proactive and check your password now, I suggest you visit Have I Been Pwned: Pwned Passwords any time.





Please support Geekzone by subscribing, or using one of our referral links: Samsung | AliExpress | Wise | Sharesies | Hatch | GoodSyncBackblaze backup


View this topic in a long page with up to 500 replies per page Create new topic
 1 | 2 | 3 | 4 | 5
gbwelly
1243 posts

Uber Geek


  #2648043 5-Feb-2021 09:59
Send private message

compromised passwords mean the password is the same as a password used in some other service that have been leaked

 

email address/username and password combo? Or if I have a collision with anyone else who has used the same password in the database I have to change mine?

 

 










freitasm

BDFL - Memuneh
79250 posts

Uber Geek

Administrator
ID Verified
Trusted
Geekzone
Lifetime subscriber

  #2648046 5-Feb-2021 10:06
Send private message

gbwelly:

 

compromised passwords mean the password is the same as a password used in some other service that have been leaked

 

email address/username and password combo? Or if I have a collision with anyone else who has used the same password in the database I have to change mine?

 

 

Password only. If you use a password that has been compromised - with anyone else's email, then it will require a reset.

 

The assumption is that if your password is common enough to match any leaked password then we will assume it's part of a dictionary now. Even though we rate limit login and ask people to use 2FA, I feel we need to get people using unique passwords.

 

This doesn't mean you can't reuse passwords  - providing a password is random enough and has not been leaked reusing passwords will not be stoped by this method as we wouldn't know it's being used somewhere else. But it is still an unsafe practice to reuse passwords because a single, unreported leak could have huge consequences.





Please support Geekzone by subscribing, or using one of our referral links: Samsung | AliExpress | Wise | Sharesies | Hatch | GoodSyncBackblaze backup


xpd

xpd
Geek @ Coastguard NZ
13765 posts

Uber Geek

Retired Mod
ID Verified
Trusted
Lifetime subscriber

  #2648047 5-Feb-2021 10:10
Send private message

Hmm maybe time for me to update passwords.... Ive been lazy and I know the one I use here has appeared in the HIBP database previously. 

 

<wil go do now>

 

 





       Gavin / xpd / FastRaccoon / Geek of Coastguard New Zealand

 

                      LinkTree

 

 

 




sidefx
3711 posts

Uber Geek

Trusted

  #2648052 5-Feb-2021 10:20
Send private message

Image result for space balls luggage combination





"I was born not knowing and have had only a little time to change that here and there."         | Octopus Energy | Sharesies
              - Richard Feynman


eracode
Smpl Mnmlst
8846 posts

Uber Geek

ID Verified
Trusted
Subscriber

  #2648053 5-Feb-2021 10:27
Send private message

xpd:

 

Hmm maybe time for me to update passwords.... Ive been lazy and I know the one I use here has appeared in the HIBP database previously. 

 

<wil go do now>

 

 

Same. Done too.





Sometimes I just sit and think. Other times I just sit.


Quinny
885 posts

Ultimate Geek

Trusted

  #2648054 5-Feb-2021 10:29
Send private message

Will this check against Two Factor use? And the list at pwned is off as I lost one in the Sony Playstation breach that is not showing 


dt

dt
1152 posts

Uber Geek
Inactive user


  #2648056 5-Feb-2021 10:31
Send private message

what a fantastic idea, nice work 


 
 
 

Cloud spending continues to surge globally, but most organisations haven’t made the changes necessary to maximise the value and cost-efficiency benefits of their cloud investments. Download the whitepaper From Overspend to Advantage now.
freitasm

BDFL - Memuneh
79250 posts

Uber Geek

Administrator
ID Verified
Trusted
Geekzone
Lifetime subscriber

  #2648060 5-Feb-2021 10:44
Send private message

Quinny:

 

Will this check against Two Factor use? And the list at pwned is off as I lost one in the Sony Playstation breach that is not showing 

 

 

2FA is still optional.

 

The list only contains password dumps that the author can get his hands on. It's practically impossible to cover all the breached passwords, ever but with their current list of 505 breaches covering 10,594,333,080 accounts it's a good chance most will be covered.





Please support Geekzone by subscribing, or using one of our referral links: Samsung | AliExpress | Wise | Sharesies | Hatch | GoodSyncBackblaze backup


freitasm

BDFL - Memuneh
79250 posts

Uber Geek

Administrator
ID Verified
Trusted
Geekzone
Lifetime subscriber

  #2648061 5-Feb-2021 10:44
Send private message

I will deploy the code and terminate all current sessions at 11am





Please support Geekzone by subscribing, or using one of our referral links: Samsung | AliExpress | Wise | Sharesies | Hatch | GoodSyncBackblaze backup


  #2648083 5-Feb-2021 11:55
Send private message

Yeah I am the same so lazy lol. Have updated mine as well as added 2FA.

 

Thanks for giving me the needed push.





Ding Ding Ding Ding Ding : Ice cream man , Ice cream man


freitasm

BDFL - Memuneh
79250 posts

Uber Geek

Administrator
ID Verified
Trusted
Geekzone
Lifetime subscriber

  #2648086 5-Feb-2021 12:02
Send private message

One hour since I have released this change. We had about 100 login attempts using compromised passwords so far - these were blocked and redirected to the information page (including links to online random password generators).  





Please support Geekzone by subscribing, or using one of our referral links: Samsung | AliExpress | Wise | Sharesies | Hatch | GoodSyncBackblaze backup


PeterReader
6018 posts

Uber Geek

Trusted
Geekzone
Lifetime subscriber

  #2648087 5-Feb-2021 12:06
Send private message

I am very happy that my computer brain created my own password and I can always remember it.





I am the Geekzone Robot and I am here to help. I am from the Internet. I do not interact. Do not expect other replies from me.

 

These links are referral codes: Sharesies | Mighty Ape 


  #2648088 5-Feb-2021 12:06
Send private message

freitasm:

 

One hour since I have released this change. We had about 100 login attempts using compromised passwords so far - these were blocked and redirected to the information page (including links to online random password generators).  

 

 

😮


Handsomedan
7281 posts

Uber Geek

ID Verified
Trusted
Subscriber

  #2648095 5-Feb-2021 12:20
Send private message

freitasm:

 

One hour since I have released this change. We had about 100 login attempts using compromised passwords so far - these were blocked and redirected to the information page (including links to online random password generators).  

 

I think about 70 of those would've been me. 

 

 

 

The remnants of a migraine are still playing havoc with my ability to function properly as a human being. 

 

 





Handsome Dan Has Spoken.
Handsome Dan needs to stop adding three dots to every sentence...

 

Handsome Dan does not currently have a side hustle as the mascot for Yale 

 

 

 

*Gladly accepting donations...


MurrayM
2455 posts

Uber Geek

ID Verified
Trusted
Lifetime subscriber

  #2648100 5-Feb-2021 12:27
Send private message

I switched to using the KeePass password safe several years ago and I let it generate long random passwords for each site that I need an account on. Since I was able to log in just fine here a few minutes ago, I assume it's doing its job!


 1 | 2 | 3 | 4 | 5
View this topic in a long page with up to 500 replies per page Create new topic





News and reviews »

Air New Zealand Starts AI adoption with OpenAI
Posted 24-Jul-2025 16:00


eero Pro 7 Review
Posted 23-Jul-2025 12:07


BeeStation Plus Review
Posted 21-Jul-2025 14:21


eero Unveils New Wi-Fi 7 Products in New Zealand
Posted 21-Jul-2025 00:01


WiZ Introduces HDMI Sync Box and other Light Devices
Posted 20-Jul-2025 17:32


RedShield Enhances DDoS and Bot Attack Protection
Posted 20-Jul-2025 17:26


Seagate Ships 30TB Drives
Posted 17-Jul-2025 11:24


Oclean AirPump A10 Water Flosser Review
Posted 13-Jul-2025 11:05


Samsung Galaxy Z Fold7: Raising the Bar for Smartphones
Posted 10-Jul-2025 02:01


Samsung Galaxy Z Flip7 Brings New Edge-To-Edge FlexWindow
Posted 10-Jul-2025 02:01


Epson Launches New AM-C550Z WorkForce Enterprise printer
Posted 9-Jul-2025 18:22


Samsung Releases Smart Monitor M9
Posted 9-Jul-2025 17:46


Nearly Half of Older Kiwis Still Write their Passwords on Paper
Posted 9-Jul-2025 08:42


D-Link 4G+ Cat6 Wi-Fi 6 DWR-933M Mobile Hotspot Review
Posted 1-Jul-2025 11:34


Oppo A5 Series Launches With New Levels of Durability
Posted 30-Jun-2025 10:15









Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.



Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.