Company
Date Published
Author
Dan Moore
Word count
1642
Language
English
Hacker News points
None

Summary

FusionAuth has implemented breached password detection to help secure user accounts by checking if a user's password is in a database of compromised credentials. This feature is available on paid plans and can be enabled through the tenant settings page, allowing users to choose how they want to respond to breached passwords during login or registration events. The feature provides real-time checks and can prevent unauthorized access to systems if a password has been compromised. It also empowers users by allowing them to pick unique and strong passwords without being restricted by certain character requirements. While enabling this check may have a slight performance impact, the benefits of increased security and user empowerment outweigh the costs.