Back to feed
Dev.to
Dev.to
7/18/2026
Building a password strength checker with ML classification and breach detection

Building a password strength checker with ML classification and breach detection

Original: I Built a Password Strength Checker That Actually Works (Here's Why Most Fail)

Short summary

A developer built a password strength checker combining a Random Forest classifier (93.3% accuracy on 28 features including entropy, bigram entropy, and keyboard-walk detection) with Have I Been Pwned breach detection. The key insight is that breach status overrides all structural metrics—a password like "Tr0ub4dor&3" scores Strong on ML but is actually compromised across 3,196 breaches. The system aligns with NIST SP 800-63B requirements that most checkers ignore.

  • Random Forest classifier trained on 150 passwords across 6 character-composition categories achieves 93.3% accuracy
  • HIBP breach detection overrides ML structural scoring—empirical compromise status is ground truth
  • Aligns with NIST SP 800-63B which requires breach checking that most password checkers skip

Generated with AI, which can make mistakes.

Is this a good recommendation for you?

Comments

Failed to load comments. Please try again.

Explore more