top | item 37796583

(no title)

mjsweet | 2 years ago

If I were operating a SaaS platform or any other online service, I'd be inclined to automatically reset passwords for users whose credentials have been compromised in a data breach. Has anyone here developed an automated system to handle this? I'm particularly curious about how one would automate the gathering of leaked databases and cross-reference user passwords against these lists, both at the point of signup and periodically thereafter. Seems like a compelling problem to solve.

discuss

order

brap|2 years ago

I don’t know if there’s a service that does that, but I do know big tech companies do exactly this for their accounts (user accounts, not just employees). Additionally many password managers will warn you, including the built in ones in iOS and Chrome.