Even though ransomware has taken over the specialized media, the theft of credentials on the Web remains as problematic as ever. Every time that happens, the user must rush to change the passwords of their most important services, but a lingering doubt is whether they were actually leaked. The excellent portal Have I Been Pwned has just integrated a database with over 300 million compromised passwords. If one of your passwords ended up in copies of malicious lists, this will help you know.

Do You Use a Password That Was Already Hacked? Look It Up in This List!
Passwords

The relationship between users and passwords has not improved in any aspect. The most important devices and operating systems on the market offer alternatives like fingerprint reading and facial recognition, but the rest of the Web continues to depend on the user-password combo. If we add the notable increase in cyberattacks and the magnitude of the breaches, the situation is quite worrying. The recommendation to use local password managers like KeePass remains firm for two reasons: the user is not forced to remember passwords, and it avoids reuse.

Do You Use a Password That Was Already Hacked? Look It Up in This List!
Remember: Don't send passwords you are currently using unless you plan to retire them.

We all understand that reusing passwords is convenient, but from a security standpoint it's a very bad idea, and if they end up exposed, they will affect several services in one move. The portal Have I Been Pwned proposes verifying whether one of our passwords is already floating on the Web. Its head Troy Hunt has always allowed us to search usernames and email addresses without references to passwords, but now he's reversing that mechanism. The new database contains over 300 million passwords obtained through dozens of attacks in recent years. If you're going to search for a password, Have I Been Pwned suggests that it not be one in active use, or that you replace it regardless of the result.

Do You Use a Password That Was Already Hacked? Look It Up in This List!
We only need two searches to detect a leaked password.

A very interesting aspect is that we can download the complete database. The original file and its immediate update exceed 5.5 GB compressed, and exceed 12 GB in plain text. The idea is that major providers turn this database into an automatic blacklist to reject any previously compromised password.

Official site: