Live data from Hacker News

A decade of Have I Been Pwned

troyhunt.com

41–50 of 181 posts

Re: A decade of Have I Been Pwned

#41

Blackmail scammers have been using pwned password databases to craft some pretty convincing phishing emails ("I have installed RAT on your system and have been watching you through your webcam, proof I hacked you: -- send $1800 of BTC to this address and don't go to the police. Maybe use a password manager next time."). Do people get caught in these scams? I assume most get blocked by spam filters. I've only noticed…

Caught, I can't say. I have heard of users becoming alarmed and running to IT for reassurance.

I got one or two of these emails, and couldn't for the life of me guess on what sites I had used the (pretty weak) passwords.

Re: A decade of Have I Been Pwned

#42

Earlier quoted context omitted.

E-mail verification would make the service much more costly to run, maybe not sustainable. If you’ve got someone’s email address, do you really need HIBP to figure out where it’s used? Wouldn’t Google give you a lot of results already?

Yes, you enter an email and you get a list of the hacks it's been found in, along with the type of data that's in the data breach. At that point you just go grab the data breach from some other location and pull the data. Including passwords, which will often be reused across other services and give you access to other accounts. The breach data (or subsequent accounts accessed from the passwords) may have a lot of ad…

“Just go grab the data breach from some other location”

Do you have examples you can point to where this has happened? I would be interested in cases where this kind of approach has been taken, as my intuition is that Troy’s service wouldn’t make this significantly easier or cheaper.

Re: A decade of Have I Been Pwned

#43

> Not to mention all the other weird variations including haveibeenburned.com, haveigotpwned.com, haveibeenrekt.com and after someone made the suggestion following the revelation that PornHub follows me, haveibeenfucked.com That is honestly pretty hilarious of a side effect of media fame!

That last one would be an interesting repository of revenge porn, although it's illegal to distribute it in a lot of jurisdictions.

Although, maybe it could be a database of facial recognition hashes from revenge porn, and you can upload a similar hash of your own face to see if you're online somewhere?

Re: A decade of Have I Been Pwned

#45

he shouldn't have mentioned goatse, or told me not to google it. my curious brain took me to a rabbit hole where several times i wished i didnt have eyes.

Let me be the one to tell you not to look up tubgirl or meatspin. The turn-of-the millennium internet was a dirty place.

When you know how old someone is by the fact they don't know any of those things.

Re: A decade of Have I Been Pwned

#46

Earlier quoted context omitted.

Yes, you enter an email and you get a list of the hacks it's been found in, along with the type of data that's in the data breach. At that point you just go grab the data breach from some other location and pull the data. Including passwords, which will often be reused across other services and give you access to other accounts. The breach data (or subsequent accounts accessed from the passwords) may have a lot of ad…

“Just go grab the data breach from some other location” Do you have examples you can point to where this has happened? I would be interested in cases where this kind of approach has been taken, as my intuition is that Troy’s service wouldn’t make this significantly easier or cheaper.

It would definitely make this significantly easier and cheaper.

Imagine you want data on a specific individual. You can locate and obtain ALL available data breaches, then search through each one individually looking for references to your target. OR, you can enter their email into a search and get back a list of which SPECIFIC data breaches have information on your target AND the types of information included in the breach. This narrows the scope of effort by orders of magnitude.

How does that not make it significantly easier and cheaper?

Re: A decade of Have I Been Pwned

#47

Troy Hunt is such a treasure. And for us web application developers, there is no excuse for not having protection against credential stuffing! While the best defense is likely two-factor [1], checking against Hunt's hashed password database is also very good and requires no extra work for users! I don't have anything to back this up, but my guess is that the vast majority of compromised user accounts comes from crede…

> ... and then realize with a horrible feeling that some % of those hits are getting through the login page. The alternative is the exact same scenario, except that the percentage is several orders of magnitude lower, right? The small subset of your users that explicitly opted-out of 2-factor authentication (if you allow that) and who try to choose "Password1!" with a second exclamation point when your site said "Err…

The bad feeling comes from knowing you could have reasonably done something to mitigate the harm. Don't let perfect be the enemy of good.

Remember that "identity theft" is marketing fluff. In a credential stuffing attack your business is the victim of fraud.

Re: A decade of Have I Been Pwned

#48

he shouldn't have mentioned goatse, or told me not to google it. my curious brain took me to a rabbit hole where several times i wished i didnt have eyes.

Let me be the one to tell you not to look up tubgirl or meatspin. The turn-of-the millennium internet was a dirty place.

make lemon parties great again

Re: A decade of Have I Been Pwned

#49

> Not to mention all the other weird variations including haveibeenburned.com, haveigotpwned.com, haveibeenrekt.com and after someone made the suggestion following the revelation that PornHub follows me, haveibeenfucked.com That is honestly pretty hilarious of a side effect of media fame!

It just proves that rules of the internet work. If it exists, there's a porn version of it.

Re: A decade of Have I Been Pwned

#50

he shouldn't have mentioned goatse, or told me not to google it. my curious brain took me to a rabbit hole where several times i wished i didnt have eyes.

what's the learning curve of a GenZer? When boomer says don't look this up on the internet, it's not because they want the information for themselves. It's because they already have something burned into the memories, and are hoping to save you from the same.
Post reply on HN