logo

Preventing Compromised Password Reuse on HackerOne.com

ID: 37f72725-e1b6-558c-9746-efebd5d96124

STIX ID: report--37f72725-e1b6-558c-9746-efebd5d96124

Feed Name: HackerOne Blog

Date Published: 2024-11-26

Date Updated: 2026-06-11

...
...

HackerOne announced an improvement to account security that blocks use of passwords known to be compromised by integrating Have I Been Pwned’s Pwned Passwords API. The site enforces a 12-character minimum and entropy checks, then computes a SHA-1 hash of the password and queries only the first five characters (k-anonymity) to check for matches without exposing the full password; users are advised to use password managers and enable multi-factor authentication.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.