Live data from Hacker News

A decade of Have I Been Pwned

troyhunt.com

31–40 of 181 posts

Re: A decade of Have I Been Pwned

#31
post #8

> Not to mention all the other weird variations including haveibeenburned.com, haveigotpwned.com, haveibeenrekt.com and after someone made the suggestion following the revelation that PornHub follows me, haveibeenfucked.com That is honestly pretty hilarious of a side effect of media fame!

> haveibeenfucked.com Years ago we had friends, a couple in which the wife was pregnant. They were actually a bit embarrassed that “everyone will know that we ‘did it’”. A level of squeamishishness I could not have imagined!

> They were actually a bit embarrassed that “everyone will know that we ‘did it’”.

Most people would be more embarrassed if the wife is clearly pregnant and nobody thinks they “did it”.

Re: A decade of Have I Been Pwned

#32

In the past decade, I wonder how many stalker victims have discovered HaveIBeenPwned as the easy directing tool that their abuser used to discover and invade their accounts and privacy.. Yes, yes, I know, the site maintains that it's the victim's responsibility, prior to any bad actor taking advantage of the service, to sign up and then disable their information from showing up in the search. Because the shock and aw…

I agree. It's kind of worse because it gives attackers 90% of the information they need, but it doesn't tell the victims what data was leaked. I want to see the hash so I can figure out which password was compromised.

Re: A decade of Have I Been Pwned

#34
post #10

It is worth noting the user awareness impact HaveIBeenPwned has had. On the other hand, I feel like SpyCloud does not get enough credit for having a dataset 30x bigger and working directly with companies to actually mitigate credential reuse. If you've ever been prompted at login to a major website or received an email asking you to reset a password because it was used in multiple places, there is a good chance SpyCl…

Hrm, a free service that helps millions of people vs a company that requires a subscription for any use. I don't think you're comparing apples to apples, and the latter is not useful at all for most people.

Re: A decade of Have I Been Pwned

#35
post #17

Earlier quoted context omitted.

> This is a call for service providers in these dumps to move to Passkeys faster Does it really matter? I think all of my accounts use 20char autogenerated passwords from google that are unique for each account. So if one is breached, it’s just breached. Seems to have the same protection as a passkey.

You are the outlier. This is not the norm. Passkeys do this for the broad public, with the keys backed up to ecosystem cloud storage and defended by strong security systems at Apple and Google. Lets not argue passkey sovereignty in this thread, there are efforts ongoing to make them exportable so you can manage them in password managers. I agree it is a valid concern to prevent ecosystems holding users hostage. Long…

People using passkeys are the outlier too.

Re: A decade of Have I Been Pwned

#36
post #35

Earlier quoted context omitted.

You are the outlier. This is not the norm. Passkeys do this for the broad public, with the keys backed up to ecosystem cloud storage and defended by strong security systems at Apple and Google. Lets not argue passkey sovereignty in this thread, there are efforts ongoing to make them exportable so you can manage them in password managers. I agree it is a valid concern to prevent ecosystems holding users hostage. Long…

People using passkeys are the outlier too.

Google (top site for internet traffic) is defaulting to Passkeys: https://blog.google/technology/safety-security/passkeys-defa... (Gmail has over 1.8 billion active users as of 2023; 22.22% of the world's population uses Google's mail service, so this is material for Passkey uptake)

Amazon: https://www.aboutamazon.com/news/retail/amazon-passwordless-...

Uber: https://help.uber.com/riders/article/using-passkeys-to-sign-...

Ebay: https://www.ebay.com/help/account/signing-account/signing-ac...

Github: https://github.blog/2023-09-21-passkeys-are-generally-availa...

Link by Stripe: https://app.link.com/

Docusign: https://www.docusign.com/blog/docusign-customers-can-upgrade...

Tiktok: https://newsroom.tiktok.com/en-us/passkeys-fido-alliance (TikTok has over 1.677 billion users globally, out of which 1.1 billion are its monthly active users)

Google's Titan key now supports Passkeys if you need a secure hardware authenticator: https://www.wired.com/story/google-titan-security-key-passke... | https://store.google.com/us/product/titan_security_key?hl=en...

Re: A decade of Have I Been Pwned

#37
Blackmail scammers have been using pwned password databases to craft some pretty convincing phishing emails ("I have installed RAT on your system and have been watching you through your webcam, proof I hacked you: -- send $1800 of BTC to this address and don't go to the police. Maybe use a password manager next time."). Do people get caught in these scams?

I assume most get blocked by spam filters. I've only noticed them when they get past SPI/DKIM filtering and I have to train more. They seem pretty clever.

I appreciate the service and enjoy Troy Hunt's posts. HIBP is great.

Re: A decade of Have I Been Pwned

#38

Troy Hunt is such a treasure. And for us web application developers, there is no excuse for not having protection against credential stuffing! While the best defense is likely two-factor [1], checking against Hunt's hashed password database is also very good and requires no extra work for users! I don't have anything to back this up, but my guess is that the vast majority of compromised user accounts comes from crede…

> ... and then realize with a horrible feeling that some % of those hits are getting through the login page.

The alternative is the exact same scenario, except that the percentage is several orders of magnitude lower, right?

The small subset of your users that explicitly opted-out of 2-factor authentication (if you allow that) and who try to choose "Password1!" with a second exclamation point when your site said "Error, your password has seen 83,000 times in password dumps, please use a unique password" will still get hacked.

Or is your expectation that no one will attack every user on your webapp with a credential stuffing attempt if they see that the probability of success is 0.001% instead of 1%?

Re: A decade of Have I Been Pwned

#39
post #17

Earlier quoted context omitted.

This is a call for service providers in these dumps to move to Passkeys faster, not for the data to be redacted or censored. You want to decay the value of the credentials as rapidly as possible once exposure has been determined. This aligns with NIST guidance around secrets rotation. Once a breach is determined, all of these passwords should be invalidated immediately and require a password reset if you're so behind…

> This is a call for service providers in these dumps to move to Passkeys faster Does it really matter? I think all of my accounts use 20char autogenerated passwords from google that are unique for each account. So if one is breached, it’s just breached. Seems to have the same protection as a passkey.

absolutely, password managers have deprecated have i been pwned. It probably does more harm than good now.

Re: A decade of Have I Been Pwned

#40

Blackmail scammers have been using pwned password databases to craft some pretty convincing phishing emails ("I have installed RAT on your system and have been watching you through your webcam, proof I hacked you: -- send $1800 of BTC to this address and don't go to the police. Maybe use a password manager next time."). Do people get caught in these scams? I assume most get blocked by spam filters. I've only noticed…

I mean, I once got an email with my password in plain text and it was pretty disturbing. I did a quick search and realized that that password wasn’t used in anything I cared about so, I just went about my day, still disturbed but knowing that it’s an old password.

I can’t imagine how it would feel if I didn’t use a password manager and couldn’t quickly see where was that password used instead of wreaking my brain trying to remember!

Post reply on HN