Pwned Passwords Padding (ft. Lava Lamps and Workers)
Blog post from Cloudflare
The Pwned Passwords API, a part of Troy Hunt's Have I Been Pwned service, has introduced padding in its responses to protect against potential attack vectors that use passive analysis of response sizes. By passing the "Add-Padding" header with a value of "true", users can request padded API responses. The padding consists of randomly generated hash suffixes with usage count set to "0". This feature is expected to be mandatory in the future, once clients have had time to update their implementations.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.