{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2021:WPF2V3GWDALLPLWCIYTFQNJK64","short_pith_number":"pith:WPF2V3GW","schema_version":"1.0","canonical_sha256":"b3cbaaecd61816b7aec2462658352af7327733c15f9aebeea0cbad440c4681fe","source":{"kind":"arxiv","id":"2109.14490","version":2},"attestation_state":"computed","paper":{"title":"Might I Get Pwned: A Second Generation Compromised Credential Checking Service","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":[],"primary_cat":"cs.CR","authors_text":"Bijeeta Pal, Christopher Wood, Luke Valenta, Marina Sanusi, Mazharul Islam, Nick Sullivan, Rahul Chattejee, Tara Whalen, Thomas Ristenpart","submitted_at":"2021-09-29T15:16:59Z","abstract_excerpt":"Credential stuffing attacks use stolen passwords to log into victim accounts. To defend against these attacks, recently deployed compromised credential checking (C3) services provide APIs that help users and companies check whether a username, password pair is exposed. These services however only check if the exact password is leaked, and therefore do not mitigate credential tweaking attacks - attempts to compromise a user account with variants of a user's leaked passwords. Recent work has shown credential tweaking attacks can compromise accounts quite effectively even when the credential stuf"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2109.14490","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2021-09-29T15:16:59Z","cross_cats_sorted":[],"title_canon_sha256":"badd8ab7fa3d585c8587d18077322a6c0840089d66104be1d96bc4cc264f2bea","abstract_canon_sha256":"878617d6acb784336d0e0dfdb17b35300b8bb318750d17e9c67b85f422138751"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T04:08:03.930253Z","signature_b64":"wLGINECTTaFWcQMsNCnBDGf95sn54iow8nb0C1WAlCUqf2PQMgWbvfykX8Kf8tZ9d99gJ6aA8T+VvDPakh3NDw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"b3cbaaecd61816b7aec2462658352af7327733c15f9aebeea0cbad440c4681fe","last_reissued_at":"2026-07-05T04:08:03.929849Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T04:08:03.929849Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Might I Get Pwned: A Second Generation Compromised Credential Checking Service","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":[],"primary_cat":"cs.CR","authors_text":"Bijeeta Pal, Christopher Wood, Luke Valenta, Marina Sanusi, Mazharul Islam, Nick Sullivan, Rahul Chattejee, Tara Whalen, Thomas Ristenpart","submitted_at":"2021-09-29T15:16:59Z","abstract_excerpt":"Credential stuffing attacks use stolen passwords to log into victim accounts. To defend against these attacks, recently deployed compromised credential checking (C3) services provide APIs that help users and companies check whether a username, password pair is exposed. These services however only check if the exact password is leaked, and therefore do not mitigate credential tweaking attacks - attempts to compromise a user account with variants of a user's leaked passwords. Recent work has shown credential tweaking attacks can compromise accounts quite effectively even when the credential stuf"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2109.14490","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2109.14490/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2109.14490","created_at":"2026-07-05T04:08:03.929904+00:00"},{"alias_kind":"arxiv_version","alias_value":"2109.14490v2","created_at":"2026-07-05T04:08:03.929904+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2109.14490","created_at":"2026-07-05T04:08:03.929904+00:00"},{"alias_kind":"pith_short_12","alias_value":"WPF2V3GWDALL","created_at":"2026-07-05T04:08:03.929904+00:00"},{"alias_kind":"pith_short_16","alias_value":"WPF2V3GWDALLPLWC","created_at":"2026-07-05T04:08:03.929904+00:00"},{"alias_kind":"pith_short_8","alias_value":"WPF2V3GW","created_at":"2026-07-05T04:08:03.929904+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":0,"internal_anchor_count":0,"sample":[]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/WPF2V3GWDALLPLWCIYTFQNJK64","json":"https://pith.science/pith/WPF2V3GWDALLPLWCIYTFQNJK64.json","graph_json":"https://pith.science/api/pith-number/WPF2V3GWDALLPLWCIYTFQNJK64/graph.json","events_json":"https://pith.science/api/pith-number/WPF2V3GWDALLPLWCIYTFQNJK64/events.json","paper":"https://pith.science/paper/WPF2V3GW"},"agent_actions":{"view_html":"https://pith.science/pith/WPF2V3GWDALLPLWCIYTFQNJK64","download_json":"https://pith.science/pith/WPF2V3GWDALLPLWCIYTFQNJK64.json","view_paper":"https://pith.science/paper/WPF2V3GW","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2109.14490&json=true","fetch_graph":"https://pith.science/api/pith-number/WPF2V3GWDALLPLWCIYTFQNJK64/graph.json","fetch_events":"https://pith.science/api/pith-number/WPF2V3GWDALLPLWCIYTFQNJK64/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/WPF2V3GWDALLPLWCIYTFQNJK64/action/timestamp_anchor","attest_storage":"https://pith.science/pith/WPF2V3GWDALLPLWCIYTFQNJK64/action/storage_attestation","attest_author":"https://pith.science/pith/WPF2V3GWDALLPLWCIYTFQNJK64/action/author_attestation","sign_citation":"https://pith.science/pith/WPF2V3GWDALLPLWCIYTFQNJK64/action/citation_signature","submit_replication":"https://pith.science/pith/WPF2V3GWDALLPLWCIYTFQNJK64/action/replication_record"}},"created_at":"2026-07-05T04:08:03.929904+00:00","updated_at":"2026-07-05T04:08:03.929904+00:00"}