<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Harmony Endpoint Passwords check in Endpoint</title>
    <link>https://community.checkpoint.com/t5/Endpoint/Harmony-Endpoint-Passwords-check/m-p/146014#M5499</link>
    <description>&lt;P&gt;Hi Everybody,&lt;/P&gt;&lt;P&gt;do you know how Harmony Endpoint (Zero-Phishing defense) works? I mean password comparing part. Does it save hash of password? and take list of internal sites from - Protected Domains and saved hash of passwords?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;</description>
    <pubDate>Mon, 11 Apr 2022 19:48:19 GMT</pubDate>
    <dc:creator>Sergo89</dc:creator>
    <dc:date>2022-04-11T19:48:19Z</dc:date>
    <item>
      <title>Harmony Endpoint Passwords check</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Harmony-Endpoint-Passwords-check/m-p/146014#M5499</link>
      <description>&lt;P&gt;Hi Everybody,&lt;/P&gt;&lt;P&gt;do you know how Harmony Endpoint (Zero-Phishing defense) works? I mean password comparing part. Does it save hash of password? and take list of internal sites from - Protected Domains and saved hash of passwords?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Mon, 11 Apr 2022 19:48:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Harmony-Endpoint-Passwords-check/m-p/146014#M5499</guid>
      <dc:creator>Sergo89</dc:creator>
      <dc:date>2022-04-11T19:48:19Z</dc:date>
    </item>
    <item>
      <title>Re: Harmony Endpoint Passwords check</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Harmony-Endpoint-Passwords-check/m-p/146016#M5500</link>
      <description>&lt;P class=""&gt;The basic flow of the “Password Reuse” feature is as follows:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;The admin defines the protected corporate domains in SBA4B policy.&lt;/LI&gt;&lt;LI&gt;A user submits his/her credentials in a form that belongs to one of the protected domains.&lt;/LI&gt;&lt;LI&gt;The password hash will be taken (sha256, hmac) and saved in local browser storage&lt;/LI&gt;&lt;LI&gt;Once the user will use the same password in a non-protected domain, the system will trigger according to configuration (log, usercheck)&lt;BR /&gt;&lt;BR /&gt;It is importent to note point#2 - the user must enter his credentials of the protected domain&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;after&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;the domain was add to the protected domains, and the configuration was synced to the extension.&lt;BR /&gt;there is no integration with AD, so the extension "learns" the password it needs to protect once the user type them in the a protected domain web site&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Source:&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/Endpoint/Password-Reuse-testing/m-p/22054/highlight/true#M3695" target="_self"&gt;https://community.checkpoint.com/t5/Endpoint/Password-Reuse-testing/m-p/22054/highlight/true#M3695&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Apr 2022 20:40:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Harmony-Endpoint-Passwords-check/m-p/146016#M5500</guid>
      <dc:creator>Luiz_</dc:creator>
      <dc:date>2022-04-11T20:40:29Z</dc:date>
    </item>
  </channel>
</rss>

