Wordfence WordPress Plugin Checks for Pwned Passwords

With the recent release of Have I been pwned version 2.0 I’ve seen a lo of articles talking about using the tools to check and see if that oh so clever password you came up with is actually so unique or if it’s appears in a data breach before. There’s also been some talk of various tools that might check that for you, perhaps having it built into password managers like 1Password, for example.

Last night I also noticed another useful place where a plugin is checking the account password you use to login to a WordPress install, and forcing a password reset if it’s found in the breached data. (Yes, I found this out when it forced a reset on one of my blogs, but I’m cool with that. Happy to have help staying safe! Obviously what I thought was a random password, was found elsewhere!)

Anyway, the plugin in question is a security plugin called Wordfence. In the chagelog for their Mar. 1 update, there’s this little nugget:

Improvement: Added a new feature to prevent attackers from successfully logging in to admin accounts whose passwords have been in data breaches.

Nice.

Similar Posts

  • Shared Links (weekly) Oct. 11, 2020

    World Mental Health Day: Leaders Must Prioritize The Whole Wellbeing Of Employees

    eDiscovery Market Trends That Can No Longer Be Ignored

    Securing Your WordPress Installation

    FBI Warning: Using Hotel Wireless Networks is Risky

    How to Recognize if Your Colleague is Struggling

    Mental health days. Meeting-free times. Companies are adding new benefits to help workers cope

    Looking back at the International Panel at Relativity Fest

    Microsoft announces new initiatives to promote cybersecurity awareness

    Facebook Introduces Mental Health Resource Hub

    How To Blog Effectively Every Time

    How to talk about mental health with your boss

    The Case for Native, I Swear

  • |

    The Truth and The Internet Aren’t the Same

    Remember that State Farm commercial with the lady who “read it on the internet, so it must be true”? The reason that line resonated with so many people is because of the ridiculousness of it. We all know that anyone can start up a website, and write anything they want, without bothering to fact check…

  • |

    Linked: 5 Ransomware Predictions for 2022

    It makes sense, for the reasons Jim points out. Your ability to collect ransom payments is diminished if the organization has backups they can simply rebuild with. So, if you can find a way to lock not just the live data, but also the backups, you stand to make more money.

    What I wonder is if this will cause organizations to look at that old-school offline backup option? Keep a copy of your data physically away from your network, locked in a drawer or closet, etc.

    But, is that even feasible any longer?

  • |

    What I’m Sharing (weekly)

    Google Has a Plan to Disrupt the College Degree?This is pretty interesting, could work, if we can get orgs to see it as “qualified”. Would open a ton of doors.
    Toward a Zoom agreement?”The purpose of a meeting is not to fill the allocated slot on the Google calendar invite. The purpose is to communicate an idea and the emotions that go with it, and to find out what’s missing via engaged conversation. If we can’t do that, let’s not meet.”
    Report: AI Company Leaks Over 2.5M Medical Records
    The Intersection of E-Discovery and Cybersecurity: You’ve Come a Long Way, Baby
    Think You Don’t Need to Preserve Slack Data for Discovery? Think Again
    There is No Such Thing as a Free Lunch in Legal Tech
    Non-Lawyer Ownership Doesn’t Guarantee More A2J?The $$ barrier to entry for someone to even be a lawyer guarantees legal services will always be expensive. #A2J will require systemic changes.
    5 Best Password Managers of 2020
    Surveys Show Technology Is The Key To Law Firm Success During COVID-19 And Beyond
    Minimize The Risk of Data Loss From Departing Employees With These Simple Checklists

  • | |

    Linked: Ongoing M365 Tenant Upgrades/Migrations

    It’s not normal for us to be using a platform that works one way, then changes and works another way two weeks later, but that is absolutely the way the Agile development is going to happen. The decision to change will be pushed by the business case for making the change, eDiscovery will be a second thought, if a thought at all.

    That means two things in my mind in addition to the things Greg lays out in his post below.

    1. You have to test, test, test. Constantly. You have to stay on top of new features, old feature changes, undocumented changes, etc.

    2. The legal industry as a whole is going to have to get a lot more comfortable with “good faith efforts” being a little more of a gray area as these changes get made. What we could collect easily before, may require a lot more time and effort today, or it may not be possible today because of a bug in a recent update.

    It’s going to happen. Whether you want to talk about M365, Google, cloud document management, cloud review platforms, or even cloud backups. Things will happen beyond our ability to control them, and those things will impact eDiscovery. Are we going to be OK accepting that?

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

To respond on your own website, enter the URL of your response which should contain a link to this post's permalink URL. Your response will then appear (possibly after moderation) on this page. Want to update or remove your response? Update or delete your post and re-enter your post's URL again. (Find out more about Webmentions.)