Jump to content
OLLI_S

Check Entries agains known Breaches

Recommended Posts

Hello,

I have a suggestion for Enpass that increases the security of passwords and alerts the user when a website was hacked and a password change is recommended.

The password manager 1Password has a feature called watchtower.
They have an internal database of security breaches (database with information about hacked websites where user-data was stolen).
In this database they store the website and also the date of the breach.

1Password stores for password entries two modification dates:

  • modification date of the password
  • modification date of the entry

1Password checks the password entries against this database.
When a website was hacked after the password was changed in 1Password, then 1Password recommends to change the password.
When the password was changed after the hack of the website, then users get no notification.
So when the entry for a page was last changed today (like added some notes), but the password itself was changed 2 years ago, then users get a warning when the website was hacked 2 weeks ago.

For the password manager KeePass there is a plugin available called HaveIBeenPwned.
The plugin and the source code are available here: https://github.com/andrew-schofield/keepass2-haveibeenpwned
This plugin downloads the public breach lists form "'have i been pwned?" and from "Cloudbleed Checker".
The plugin checks (on demand) your passwords against these lists.

In KeePass there is no modification date of the password.
To get the modification date of the password the plugin checks the history of each entry and compares the passwords (to find out the modification date of the password).

Suggestion:
Please add also such a feature in Enpass in the Password Audits.
In my opinion it is OK if you use the public available lists from "'have i been pwned?" and from "Cloudbleed Checker" (like the KeePass Plugin).
This requires that you also store the "password modification date".

When you import entries from KeePass then you should also determine the password modification date of the entry.
In the KeePass XML the complete history is also exported.


Regards

OLLI

  • Like 1

Share this post


Link to post
Share on other sites

Hello,

today I read in the media that there was a large data breach where 773 Million User Records were stolen:
https://www.troyhunt.com/the-773-million-record-collection-1-data-reach/

In the article I can read:
In total, there are 1,160,253,228 unique combinations of email addresses and passwords.
The unique email addresses totalled 772,904,991. 

So a breach check that works with URLs (like described above) would really be helpful.
Especially when you actively warn the user.

Best regards

OLLI

Share this post


Link to post
Share on other sites

Hey @OLLI_S,

The features for checking pwned passwords have already available in the Enpass. You can check under the ≡ menu from the toolbar -->  select Tools → Check for Pwned Passwords. For more details please have a look at our user manual.

Pwned passwords will be shown in Weak section of audit.

Thanks!

Share this post


Link to post
Share on other sites

Hello @Anshu kumar,

1Password and also the HaveIBeenPwnd plugin for KeePass check all my passwords agains HaveIBeenPwnd and warn me when I have not changed my passwords after the breach.

When any website gets hacked in December 2018 and I changed my password in October 2018 (before the breach), then I get a warning.
When I have changed the password in January 2019 (after the breach), then I don't get a warning.

So 1Password and the HaveIBeenPwnd plugin for KeePass remind me to change the password when a specific website gets hacked.
I am not a security expert but checking if the URL got hacked is different than checking if any passwords are found in the big password leag (from multiple sources).

This is the reason why the HaveIBeenPwnd plugin for KeePass offers 3 different menu entries:

  • Site/Domain based
  • Username based
  • Password based

Details see https://github.com/andrew-schofield/keepass2-haveibeenpwned

Best regards

OLLI

Share this post


Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×