You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
@jmanico the current requirement says (emphasis mine):
2.1.14 Verify that passwords submitted during account registration or password changes are checked against a set of breached username/password pairs. (C6)
The links above only include passwords and not usernames so I am not sure they are useful for this control. Or did we mean to use this in reference to the following requirement:
2.1.7 [MODIFIED, SPLIT TO 2.1.14] Verify that passwords submitted during account registration or password change are checked against an available set of, at least, the top 3000 passwords.
Resources to consider:
https://github.com/danielmiessler/SecLists/tree/master/Passwords
https://www.ncsc.gov.uk/blog-post/passwords-passwords-everywhere#:~:text=PwnedPasswordsTop100k.txt
cc: @cmlh
The text was updated successfully, but these errors were encountered: