Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Then add NIST to the list of people you should be reaching out to (report linked from the homepage of pwnedpasswords):

https://www.nist.gov/itl/tig/projects/special-publication-80...




Indeed. One of the authors of 800-63B is actively involved in the password-research community, and is already aware that the guidance places no restrictions on blacklist size.




Consider applying for YC's Fall 2025 batch! Applications are open till Aug 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: