Live data from Hacker News

Have I Been Pwned 2.0

troyhunt.com

11–20 of 323 posts

Re: Have I Been Pwned 2.0

#11
Does anyone else feel like the new design feels less trustworthy? I've probably just been conditioned on too many templates that all look the same, and there's nothing inherently wrong with it, yet it makes me wonder if I've accidentally opened a ripoff instead of the real thing.

Re: Have I Been Pwned 2.0

#12

Amazing that even within the last decade a site as large as LinkedIn could be storing unsalted passwords. How does anyone fail at this in the modern era?

> How does anyone fail at this in the modern era?

Most probably some ancient legacy mainframe or whatnot other integration that nobody really has the time and budget to clean up and migrate to something more modern.

The larger the company, the larger the risk for ossification of anything deemed "business critical" because even a minuscule outage of one hour now is six if not seven figures worth of "lost" time.

Re: Have I Been Pwned 2.0

#14

Amazing that even within the last decade a site as large as LinkedIn could be storing unsalted passwords. How does anyone fail at this in the modern era?

They must have not asked enough Leetcode Hard questions in interviews.

Re: Have I Been Pwned 2.0

#16

Does anyone else feel like the new design feels less trustworthy? I've probably just been conditioned on too many templates that all look the same, and there's nothing inherently wrong with it, yet it makes me wonder if I've accidentally opened a ripoff instead of the real thing.

No, I agree. This new version looks like someone using a cheap template with cheap gradients (I don’t know how else to describe the gradients), and it immediately makes it look less trustworthy.

Re: Have I Been Pwned 2.0

#17
The new design looks great, and I always love following Troy's updates (although sometimes with semi-morbid curiosity).

I do find the timeline to be a little confusing- it seems to be ordered from earliest breach to most recent, but the dates on the timeline don't match that, as they seem to be when the data was leaked?

Display: breach date Ordering: breach published date?

I think it might be clearer to order + display the published date, and in the cards themselves show the breach date in a standard way.

Re: Have I Been Pwned 2.0

#18

It shows you a vertically scrolling timeline (with logos and blurbs) of all the data breaches that have exposed your email. How delightfully horrifying.

Makes me feel a little powerless. The only thing I can really do is freeze my credit

what?

Why not just use different passwords for different things. I'd recommend something like privacy.com so you can generate a bunch of one-use cc cards when doing shopping on sites you don't trust and the like.

Also don't willingly give up valuable personal information unless it's absolutely necessary, it's also not illegal to give online services outright false information (incorrect birthdates for example) which, in the event of a future data breach of that service, now at least those who would plan to benefit from your personal information might have some difficulties resetting important accs and the like.

You just gotta be smart, it's not about being powerless, HIBP and the service is just one tool to make you aware of what's out there before it gets used against you. (I would highly recommend setting up notifications for important e-mail addresses)

Re: Have I Been Pwned 2.0

#19
post #14

Amazing that even within the last decade a site as large as LinkedIn could be storing unsalted passwords. How does anyone fail at this in the modern era?

They must have not asked enough Leetcode Hard questions in interviews.

I am stealing this. Made my day :)

Re: Have I Been Pwned 2.0

#20

Does anyone else feel like the new design feels less trustworthy? I've probably just been conditioned on too many templates that all look the same, and there's nothing inherently wrong with it, yet it makes me wonder if I've accidentally opened a ripoff instead of the real thing.

No, I agree. This new version looks like someone using a cheap template with cheap gradients (I don’t know how else to describe the gradients), and it immediately makes it look less trustworthy.

[deleted]
Post reply on HN