Passbolt: a bold use of HaveIBeenPwned
blog.quarkslab.com | incident | #privacy | #password-cracking | #k-anonymity | #password-manager | #passbolt | #haveibeenpwned
Summary
Quarkslab shows Passbolt's use of the Pwned Passwords API leaked the passwords it checked: an observer of API queries could recover an 11+ character password via incremental search; fixed in v4.6.2.
- Published
- Collected
Skip to content