Data Privacy & Protection Compliance
Privacy-Preserving Compromised Credential Checking

Privacy-Preserving Compromised Credential Checking

10/14/2021 · Luke Valenta, Cefan Daniel Rubin, Christopher Wood

What this post added

This post introduces MIGP (Might I Get Pwned), a new privacy-preserving compromised credential checking protocol. It details the motivation for such a protocol, the threat of data breaches and credential stuffing, and the limitations of existing services. The post explains the MIGP protocol's advancements, including its ability to check for similar passwords (not just exact matches) and its privacy-preserving properties (no password information leaked, minimal username information leaked). It also discusses breach extraction attacks and countermeasures. Finally, it announces the public demo and open-sourced Go implementation of MIGP, and its deployment within Cloudflare's infrastructure.

Read the original post ↗