logo

332 Prevent the use of breached passwords


Summary

The system must check new passwords against a list of 1,000 to 10,000 breached passwords.


Description

There are various mechanisms for cracking passwords that use public lists containing breached credentials. Systems must check submitted passwords against some of these lists and prevent account creation and password update operations that use passwords contained in them.


Supported In

Essential: True

Advanced: True


References


Weaknesses


Last updated

2023/09/18