Trust

Passwords found in data breaches

WorkBOS refuses a password that appears in public lists of passwords stolen from other websites wherever you choose one in WorkBOS, and it tells you when the password you already use is on one.

  • Where it applies: creating an account, joining from an invitation, resetting a forgotten password, and changing it in Settings ▸ Security ▸ Password. If the password is on the lists, WorkBOS says it has appeared in a data breach: choose a different one.
  • Why it matters: robots attacking websites try the passwords on those lists first, on every site, however long or clever they look. A password on them is not safe anywhere, including the other places you use it.
  • When you sign in: WorkBOS checks the password you used. If it is on the lists you are still signed in, and asked to change it straight away. You also get an email (at most once a week), and Settings ▸ Security says so until you change it.
  • How it is checked privately: WorkBOS scrambles your password into a fingerprint and asks the Have I Been Pwned list about only the first five characters of that fingerprint. The list answers with hundreds of possible matches and WorkBOS compares them itself, so your password is never sent anywhere. If the list cannot be reached, nobody is stopped.
  • Owners and admins: Administration ▸ Security centre ▸ Overview lists who in your workspace signed in with a password on the lists, whether they use two-step sign-in, and since when. Ask them to change it; they leave the list as soon as they do.
  • Signing in with Google: you have no WorkBOS password, so there is nothing to check.

The best defence: a different password for every site, made and remembered by a password manager, and two-step sign-in (Settings ▸ Security), which keeps your account safe even when a password leaks.

Was this page useful?