Compromised Password Detection
Rolled out compromised-password checks across Rippling with a phased migration for existing password-auth users.
Overview
Compromised-password reuse is an account-access risk on password-auth flows. I built checks at login and password-change time and planned the rollout around account-access safety.
What I built
The checks used a compromised-password signal during login and password changes. For existing users, the rollout needed as much attention as the check itself: immediately blocking login would leave affected users dealing with a new access problem before they had a chance to change their password.
I used a feature flag to stage enforcement, beginning with the password-change path. For login, we introduced prompts before moving to hard blocks. That warning period gave existing users time to change their passwords before login enforcement took effect.
Outcome
- Compromised-password detection shipped on the enforced login and password-change paths.
- Login prompts gave affected password-auth users a migration path before hard login enforcement.
- The phased rollout informed later auth security rollouts by separating warning, migration, and hard-enforcement phases.
Building the check was the smaller engineering task; moving existing users through staged enforcement took months. For later security migrations, the access plan became part of the feature definition.