|
|
|
|
|
by adameasterling
990 days ago
|
|
Websites should mitigate credential stuffing by checking against known cracked passwords. All you have to do is download Troy Hunt’s hashed password database, check it when someone logs in and if it’s cracked do your email password reset flow. Or you can use their API. It’s very simple, and I believe has been an accepted best practice since like 2017. This is 100% on 23andme. They are responsible. 1. https://haveibeenpwned.com/Passwords |
|