Live data from Hacker News

A decade of Have I Been Pwned

troyhunt.com

11–20 of 181 posts

Re: A decade of Have I Been Pwned

#11
post #8

> Not to mention all the other weird variations including haveibeenburned.com, haveigotpwned.com, haveibeenrekt.com and after someone made the suggestion following the revelation that PornHub follows me, haveibeenfucked.com That is honestly pretty hilarious of a side effect of media fame!

> haveibeenfucked.com Years ago we had friends, a couple in which the wife was pregnant. They were actually a bit embarrassed that “everyone will know that we ‘did it’”. A level of squeamishishness I could not have imagined!

Haha, yes, for the same reason it used to be rude to ask "when are you expecting?", especially if newly married

Re: A decade of Have I Been Pwned

#12
post #9
post #6

Earlier quoted context omitted.

Seems slightly useless to opt-out of HIBP when your email is still in Collection #1 or Anti Public Combo List or whatever. Anyone wanting to do something nefarious with the emails will surely download the full source lists rather than try and scrape the aggregation site.

he's become a very tempting target in himself that gets more tempting with each additional database added I wonder if he actually deletes the data...

This is a call for service providers in these dumps to move to Passkeys faster, not for the data to be redacted or censored. You want to decay the value of the credentials as rapidly as possible once exposure has been determined. This aligns with NIST guidance around secrets rotation.

Once a breach is determined, all of these passwords should be invalidated immediately and require a password reset if you're so behind you're not offering Passkeys or SSO. Rate limiting will slow credential spraying attacks, but the only way to eliminate them is to use SSO ("Login with") or Passkeys. You are negligent as a provider if you are not invalidating leaked credentials in a timely manner.

https://pages.nist.gov/800-63-FAQ/#q-b05

> “Verifiers SHOULD NOT require memorized secrets to be changed arbitrarily (e.g., periodically). However, verifiers SHALL force a change if there is evidence of compromise of the authenticator.”

> Users tend to choose weaker memorized secrets when they know that they will have to change them in the near future. When those changes do occur, they often select a secret that is similar to their old memorized secret by applying a set of common transformations such as increasing a number in the password. This practice provides a false sense of security if any of the previous secrets has been compromised since attackers can apply these same common transformations. But if there is evidence that the memorized secret has been compromised, such as by a breach of the verifier’s hashed password database or observed fraudulent activity, subscribers should be required to change their memorized secrets. However, this event-based change should occur rarely, so that they are less motivated to choose a weak secret with the knowledge that it will only be used for a limited period of time.

Re: A decade of Have I Been Pwned

#13
post #10

It is worth noting the user awareness impact HaveIBeenPwned has had. On the other hand, I feel like SpyCloud does not get enough credit for having a dataset 30x bigger and working directly with companies to actually mitigate credential reuse. If you've ever been prompted at login to a major website or received an email asking you to reset a password because it was used in multiple places, there is a good chance SpyCl…

>On the other hand, I feel like SpyCloud does not get enough credit for having a dataset 30x bigger and working directly with companies to actually mitigate credential reuse

Not sure if it is your intent, but this implies that HIBP does not work directly with companies to mitigate credential re-use. It does. Some examples would be their partnership with 1Password and other password managers, Firefox, their partnership with the FBI, UK & Australian governments, etc.

Re: A decade of Have I Been Pwned

#14
post #5
post #4

For those privacy focused, here's how you can remove your information from their public search ability. https://haveibeenpwned.com/OptOut

You have to solve a Google ReCaptcha though, which privacy-focused folks won’t like. Also, just FYI, “The controller of the domain your email address is on will still see you in domain searches.”

[deleted]

Re: A decade of Have I Been Pwned

#15
In the past decade, I wonder how many stalker victims have discovered HaveIBeenPwned as the easy directing tool that their abuser used to discover and invade their accounts and privacy..

Yes, yes, I know, the site maintains that it's the victim's responsibility, prior to any bad actor taking advantage of the service, to sign up and then disable their information from showing up in the search.

Because the shock and awe of other users seeing 'Your info is out there!' immediately after entering their address, instead of after some kind of email verification, is more important than user safety.

Re: A decade of Have I Been Pwned

#16
I really like his informative posts. I remember reading about how he used k-anonymity to check passwords against the pwned file without having to transmit the passwords and it led to me studying that and later using it for some professional projects.

I sometimes think what I would have done had I never read his posts about checking without transmitting real PII.

Re: A decade of Have I Been Pwned

#17
post #9

Earlier quoted context omitted.

he's become a very tempting target in himself that gets more tempting with each additional database added I wonder if he actually deletes the data...

This is a call for service providers in these dumps to move to Passkeys faster, not for the data to be redacted or censored. You want to decay the value of the credentials as rapidly as possible once exposure has been determined. This aligns with NIST guidance around secrets rotation. Once a breach is determined, all of these passwords should be invalidated immediately and require a password reset if you're so behind…

> This is a call for service providers in these dumps to move to Passkeys faster

Does it really matter? I think all of my accounts use 20char autogenerated passwords from google that are unique for each account. So if one is breached, it’s just breached. Seems to have the same protection as a passkey.

Re: A decade of Have I Been Pwned

#18
post #17

Earlier quoted context omitted.

This is a call for service providers in these dumps to move to Passkeys faster, not for the data to be redacted or censored. You want to decay the value of the credentials as rapidly as possible once exposure has been determined. This aligns with NIST guidance around secrets rotation. Once a breach is determined, all of these passwords should be invalidated immediately and require a password reset if you're so behind…

> This is a call for service providers in these dumps to move to Passkeys faster Does it really matter? I think all of my accounts use 20char autogenerated passwords from google that are unique for each account. So if one is breached, it’s just breached. Seems to have the same protection as a passkey.

You are the outlier. This is not the norm. Passkeys do this for the broad public, with the keys backed up to ecosystem cloud storage and defended by strong security systems at Apple and Google. Lets not argue passkey sovereignty in this thread, there are efforts ongoing to make them exportable so you can manage them in password managers. I agree it is a valid concern to prevent ecosystems holding users hostage.

Long strings in password managers was a shim until Passkeys got here, because passwords suck. This is a well worn path in enterprise with PKI. Passkeys are PKI for the Average Joe. Folks here will always have esoteric auth use cases, but you design for the average on this topic (consumer auth).

https://passkeys.directory/

https://passkeys.2fa.directory/us/

https://bitwarden.com/blog/a-closer-look-at-password-statist...

> 19% of respondents said they used “password” as their password (!!!)

> 52% use easily identifiable information in their passwords, such as company/brand names, well-known song lyrics, pet names, and names of loved ones

> Best practices are still diluted by bad habits, with 85% reusing passwords across multiple sites and 58% relying on memory for their passwords

> A majority (68%) of respondents manage passwords for 10+ sites or apps and yet 84% of respondents reuse passwords

> More than half of respondents forget and reset their passwords on a regular basis

> Around a quarter (20%) were affected by breaches and a majority (80%) were prompted to reset their passwords

> Over half (56%) are excited about passwordless options, and 50% are using or would use ‘something you are’ forms of passwordless authentication

Re: A decade of Have I Been Pwned

#19
Troy Hunt is such a treasure. And for us web application developers, there is no excuse for not having protection against credential stuffing! While the best defense is likely two-factor [1], checking against Hunt's hashed password database is also very good and requires no extra work for users!

I don't have anything to back this up, but my guess is that the vast majority of compromised user accounts comes from credential stuffing/password re-use. It's really surprising to me when I hear that huge companies don't do this check.[2] It's simple, easy, takes about a day to set up.

If you're a young CTO or early-stage engineer working on a web app and have never been targeted with a credential stuffing attack, let me tell you: It's coming! It's just a matter of time before it's 1AM and your phone blows up; your site is getting hammered; you think it's DDOS, but then realize most of the hits are on your login page, then realize that and then realize with a horrible feeling that some % of those hits are getting through the login page. You'll be up all night dealing with it, and then you have to make breach notifications, and that really sucks.

Troy Hunt's free database will save you that heartache (probably). Just do it.

1. https://cheatsheetseries.owasp.org/cheatsheets/Credential_St...

2. Like 23andMe. https://news.ycombinator.com/item?id=37794379

Re: A decade of Have I Been Pwned

#20
post #13
post #10

It is worth noting the user awareness impact HaveIBeenPwned has had. On the other hand, I feel like SpyCloud does not get enough credit for having a dataset 30x bigger and working directly with companies to actually mitigate credential reuse. If you've ever been prompted at login to a major website or received an email asking you to reset a password because it was used in multiple places, there is a good chance SpyCl…

> On the other hand, I feel like SpyCloud does not get enough credit for having a dataset 30x bigger and working directly with companies to actually mitigate credential reuse Not sure if it is your intent, but this implies that HIBP does not work directly with companies to mitigate credential re-use. It does. Some examples would be their partnership with 1Password and other password managers, Firefox, their partnersh…

It would be like comparing HN to Facebook, they are both technically operating social media sites but I don't think anyone would argue they are doing so at the same scale. HIBP ultimately is a hobby project that was really good at bringing the publics attention to the problem and booting Troy's social profile.
Post reply on HN