
10/14/2021 · Luke Valenta, Cefan Daniel Rubin, Christopher Wood
What this post added
This post introduces MIGP (Might I Get Pwned), a new privacy-preserving compromised credential checking protocol. It details the motivation for such a protocol, the threat of data breaches and credential stuffing, and the limitations of existing services. The post explains the MIGP protocol's advancements, including its ability to check for similar passwords (not just exact matches) and its privacy-preserving properties (no password information leaked, minimal username information leaked). It also discusses breach extraction attacks and countermeasures. Finally, it announces the public demo and open-sourced Go implementation of MIGP, and its deployment within Cloudflare's infrastructure.