Live data from Hacker News

Should I Change My Password?

shouldichangemypassword.com

91–100 of 104 posts

Re: Should I Change My Password?

#91
So why should I trust someone who asks me to type my password into a random site? Just because he/she says they will not save it?

If you've entered your real password(s) there, you've already failed the test.

Also a whois on that domain doesn't even return a person's information, some proxied info only (might be scared of law enforcement since he might have the hacked DB data, but even so, if I didn't trust it, I trust it even less now).

Re: Should I Change My Password?

#92
post #73

Terrible interface. I entered "password" and it told me "It looks like your passwords may be safe. No instances of compromise are recorded in this database. However, it's good practice to change your critical passwords regularly and ensure they are not re-used across multiple sites." Why did I not enter an e-mail address like the light text in the input box says? Well, I let myself mislead by the header image.

You know it clearly says to enter your email address in the input field, right? Of course "password" hasn't shown up in the database…it's not an email address.

It's not clear at all. The only information that you should provide your email is that placeholder, which on my monitor is barely visible. The name and information is very misleading. Seriously, i think many people will enter their passwords there (at least those type of people who don't know they shouldn't provide passwords anywhere ).

Re: Should I Change My Password?

#93

So why should I trust someone who asks me to type my password into a random site? Just because he/she says they will not save it? If you've entered your real password(s) there, you've already failed the test. Also a whois on that domain doesn't even return a person's information, some proxied info only (might be scared of law enforcement since he might have the hacked DB data, but even so, if I didn't trust it, I tru…

You enter your email address, not your password.

Re: Should I Change My Password?

#94
post #93

So why should I trust someone who asks me to type my password into a random site? Just because he/she says they will not save it? If you've entered your real password(s) there, you've already failed the test. Also a whois on that domain doesn't even return a person's information, some proxied info only (might be scared of law enforcement since he might have the hacked DB data, but even so, if I didn't trust it, I tru…

You enter your email address, not your password.

My bad then.

Re: Should I Change My Password?

#95
Thanks for all the feedback guys, your comments are noted. We're working hard on the next iteration of the website as well as trying to ease general concerns about whether we store passwords etc at this point. Please drop twitter: @dagrz a line if you have a direct question or want to keep up with how we're tracking on the project! Thanks for the discussion all!

Re: Should I Change My Password?

#96
post #72

Earlier quoted context omitted.

What he means is this: you subscribe by telling the site your email. Then, if they ever find your email in one of the publicly released documents, then they will notify you by email.

What if your email is the account being compromised?

I guess thats why you might add a mobile number

Re: Should I Change My Password?

#97

Earlier quoted context omitted.

I still don't understand. Why?

The OP comment was: "It'd be cool if they added an option to subscribe for $10/year for a quick SMS and email notification if your account is compromised. I'd get it for myself and my family." To enable this - you are giving your email, password, Payment details and Cell Phone number. The site as it stands today doesn't ask for any of this -- but if they were to take payments and do SMS notification they would.

If we decided to do notifications I would expect users to not re-use passwords from other sites. I would also expect that such a service would require a trusted security brand behind it to work.

Re: Should I Change My Password?

#98
post #92

Earlier quoted context omitted.

You know it clearly says to enter your email address in the input field, right? Of course "password" hasn't shown up in the database…it's not an email address.

It's not clear at all. The only information that you should provide your email is that placeholder, which on my monitor is barely visible. The name and information is very misleading. Seriously, i think many people will enter their passwords there (at least those type of people who don't know they shouldn't provide passwords anywhere ).

Its true, a small number of people enter their passwords. The site has been updated with a quick check to prevent such behaviour. Thanks for the feedback.

Re: Should I Change My Password?

#100
post #66
post #26

Earlier quoted context omitted.

I think the site is referring to some service/site that got hacked recently and that you signed up for with the first-name@[domain].com email adress and not to the email account itself.

Then it makes it COMPLETELY useless information. You know how many thousands of sites I used various email addresses on, clearly everyone else is the same. It should tell you which sites were compromised such that you can ID if you used your email at any of said sites. Just saying ambiguously that there was a site which may have been compromised out of the 2 billion sites online is laughable.

I would argue that it's not completely useless as the average person re-uses the same password everywhere. Even if you do it across a small number of sites it could easily start a chain reaction.

In fact, I would say that prompting the average person to change some passwords either way, is a good thing.

Post reply on HN