Preventing Compromised Password Reuse on HackerOne.com
ID: 37f72725-e1b6-558c-9746-efebd5d96124
STIX ID: report--37f72725-e1b6-558c-9746-efebd5d96124
Feed Name: HackerOne Blog
HackerOne announced an improvement to account security that blocks use of passwords known to be compromised by integrating Have I Been Pwned’s Pwned Passwords API. The site enforces a 12-character minimum and entropy checks, then computes a SHA-1 hash of the password and queries only the first five characters (k-anonymity) to check for matches without exposing the full password; users are advised to use password managers and enable multi-factor authentication.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
