Quantcast
Channel: Hacker News
Viewing all articles
Browse latest Browse all 25817

Show HN: Evilpass – A slightly evil password strength checker

$
0
0

README.md

Checks how strong your user's password is via questionably ethical means.

Usage

Please don't actually use this.

>>>from evilpass import check_pass>>> errors = check_pass("password", "email address", "username")>>> errors
["Your password must be at least 8 characters long"]

Password reuse is bad, okay?

So quit doing it. Use a password manager. I personally recommendpass.

Side note

If you're actually checking user's password strength on sign up, I strongly suggest using a minimum entropy instead of contrived rules like this. I also suggest not trying to log into your user's account on other sites.

Future development

  • Automate use of proxies to avoid rate limiting and other things external services might do when they detect you're doing this
  • Add other external services to check (I spent about 5 minutes on Google before I decided it wasn't worth the time required to reverse engineer their login flow, but it might be the most valuable account to try)
  • Store valid credentials in a database for evil purposes

https://www.xkcd.com/792/


Viewing all articles
Browse latest Browse all 25817

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>