GitHub will now tell you if your password has been pwned
blog.github.com
blog.github.com
That being said, what I really want to see someone do is make an Active Directory plugin for Pwned Passwords. Corporate networks are both most at risk and most often where you find bad passwords.
There's significant problems with all of those views, and while arguing about each one would be a larger discussion, Troy's behavior towards people who don't agree with him is concerning.
If that's the case, then you should probably be more clear. He ridicules people for not using HTTPS is a much weaker claim than that he ridicules people for not agreeing with his security principles.
First and foremost: Password managers create a huge single point of failure. Every password manager has had security vulnerabilities, and of course, if it's cloud-based, it's far easier to gain access to it. You think password reuse is bad, try a password manager, where all of your passwords are only exactly as secure as your master, your only real password. And this leads you to treat all your accounts similarly, when in fact, many of them are more important than others.
So password managers are a bad solution, and they're a bad solution to a problem that otherwise takes over the password reuse issue: Security exhaustion. When confronted with extreme complication, frustrated users will fall back to something poor to keep themselves sane. (See the common "season + year" password format that constantly defeated password rotation as being a good idea. It met complexity requirements and rotated, but was a terrible password.)
There are passwords that should always be unique, your email, your web hosting, your bank, etc. But rather than waste effort ensuring every account known to mankind has a unique password, you should consider how many of your accounts matter. Your HN account probably doesn't matter. If you don't store your credit card details with a site, your random retailer account probably doesn't matter. (Go ahead, log into my Target account, see what you can do with it that harms me. You'll learn I once bought a Taylor Swift album, and everything else was already contained in public records.)
You are far better off reducing the impact of an account breach affecting your security and privacy than trying to ensure your account on any given website is ironclad. And for most people, I'd recommend a scrap of paper in their wallet with some key passwords over a password manager.
Also, a bonus fun fact: I changed my email address about three years ago, and have yet to receive an HIBP breach notification for it. So while I'm regularly getting breach notifications for loss of passwords from time to time, none of them are tied to my current email address for the past few years. Which is to say, if you do have a handful of reused passwords, and you rotate them every couple of years on whatever accounts you're currently interacting with, even your low security accounts are very unlikely to be breached because the data that gets passed around tends to be fairly old.
I'm not trying to say I'm the definitive expert on online security by any means, but treating the currently accepted practices as the be-all-end-all is bad, and bullying people for disagreeing with them is even worse.
I guess that most website should do the same and progressively warn users that their password is weak and is listed in a popular password list.
Of course it's bothering users, but frankly it should be done.
It seems so weird to me that the passwords are not hashed leaving the client, and it’s considered good practice.
if you just pass the hash back to the server, you can't verify that the password was secure.
More serious reason is imo js requirement, as I'm not aware of native support of password hashing in HTML forms. Also, different ways of hash keying/salting would make it either complicated or inflexible..
As long as the password is sent over a secure channels (TLS) and doesn't leak somewhere on the server (e.g. logs), sending it plaintext from the client is not where most password breaches come from. But stuff like https://en.wikipedia.org/wiki/Secure_Remote_Password_protoco... would provide a solution for that.