Small bug report: I've been pwnd a few dozens times, and my timeline is not in calendar order. I see Adobe (October 2013), then LinkedIn (May 2012), then Dropbox (June 2012), then Lastfm (March 2012), then some 2016 ones, then Kickstarter in 2014, and then after that they start being more in order of the listed dates.
Have I Been Pwned 2.0
21–30 of 323 posts
Re: Have I Been Pwned 2.0
#22Tie in to a banking service, so you can do direct deposits to many millions of people, every time there's new settlements paid, and you'll be a folk hero.
Get lawyers who want negligent companies to actually regret the breaches, with judgements that hurt. (Rather than a small settlement that gets lawyers paid, but is only a small cost of doing business, which is preferable to doing business responsibly.)
Optional: Sell data of imminent lawsuits, to an investment firm.
Though, ideally, investors won't need this data, since everyone will know that a breach means a stock should take a hit. Isn't that how it should be.
Re: Have I Been Pwned 2.0
#23Re: Have I Been Pwned 2.0
#24Re: Have I Been Pwned 2.0
#25Is there a term for this trend in web design, with defaulting to dark mode and having slick gradients everywhere?
https://medium.com/design-bootcamp/the-rise-of-linear-style-...
Re: Have I Been Pwned 2.0
#26I regularly use plus codes on my email addresses when I sign up for services, is there a way to search for an email address and all associated plus codes? Last I checked I couldn’t find that functionality.
Re: Have I Been Pwned 2.0
#27Amazing that even within the last decade a site as large as LinkedIn could be storing unsalted passwords. How does anyone fail at this in the modern era?
> How does anyone fail at this in the modern era? Most probably some ancient legacy mainframe or whatnot other integration that nobody really has the time and budget to clean up and migrate to something more modern. The larger the company, the larger the risk for ossification of anything deemed "business critical" because even a minuscule outage of one hour now is six if not seven figures worth of "lost" time.
Re: Have I Been Pwned 2.0
#28Can we make it so that companies I've never heard of before don't have my data in the first place?
Re: Have I Been Pwned 2.0
#29Earlier quoted context omitted.
Makes me feel a little powerless. The only thing I can really do is freeze my credit
what? Why not just use different passwords for different things. I'd recommend something like privacy.com so you can generate a bunch of one-use cc cards when doing shopping on sites you don't trust and the like. Also don't willingly give up valuable personal information unless it's absolutely necessary, it's also not illegal to give online services outright false information (incorrect birthdates for example) which,…
My card has been skimmed a couple of times and by far the most annoying part of the experience is having to reset and update regular accounts with the new number.
Of course for online purchases the whole flow here should be inverted: businesses should just be registering against my payment provider directly, no account numbers involved (under the hood maybe have it be managed by ED25519 public keys for identity?)
EDIT: while we're at it, why even have persistent numbers for in person cards? Let me tap it against my phone, invalidate the stored key from that time on, and generate a new one.
Re: Have I Been Pwned 2.0
#30> But now it's on a timeline you can scroll through in reverse chronological order, with each breach summarising what happened. Maybe I'm reading it wrong but it looks like it might be a little off. I get: - October 2013 - June 2008 - ...a bunch more... - November 2021 - December 2020