Live data from Hacker News

Have I Been Pwned 2.0

troyhunt.com

31–40 of 323 posts

Re: Have I Been Pwned 2.0

#31
Who has the record for being in the most breaches? My main email seems to currently be in 40 breaches, earliest one in from June 2011 (HackForums, don't even remember what that is), and last one in September 2024 (FrenchCitizens, although I'm not French nor have I ever lived in France).

Re: Have I Been Pwned 2.0

#32
post #3

Is there a term for this trend in web design, with defaulting to dark mode and having slick gradients everywhere?

I think GitHub kinda did it first on their desktop home page, but that has been out for years.

I actually think I saw it on Linear (the issue tracker app) first. Who knows

Re: Have I Been Pwned 2.0

#33
post #29
post #18

Earlier quoted context omitted.

what? Why not just use different passwords for different things. I'd recommend something like privacy.com so you can generate a bunch of one-use cc cards when doing shopping on sites you don't trust and the like. Also don't willingly give up valuable personal information unless it's absolutely necessary, it's also not illegal to give online services outright false information (incorrect birthdates for example) which,…

Application specific credit card numbers really needs to be a legally required thing. My card has been skimmed a couple of times and by far the most annoying part of the experience is having to reset and update regular accounts with the new number. Of course for online purchases the whole flow here should be inverted: businesses should just be registering against my payment provider directly, no account numbers invol…

> Application specific credit card numbers really needs to be a legally required thing.

My latest card (debit) one has a feature I've not seen elsewhere, but I think kind of solves that too. It has a new CVC number every 10 minutes, which I kind of both hate and love. Love it for the obvious reasons of "not even having the physical card lets you use it digitally" but also because I cannot have it 100% in my password manager, I have to use the banking app to get the latest CVC code when I need it.

Re: Have I Been Pwned 2.0

#34
post #22

He should partner with a law firm, for class action lawsuits, for every breach due to negligence (which is probably all of them). Tie in to a banking service, so you can do direct deposits to many millions of people, every time there's new settlements paid, and you'll be a folk hero. Get lawyers who want negligent companies to actually regret the breaches, with judgements that hurt. (Rather than a small settlement th…

> do direct deposits to many millions of people, every time there's new settlements paid

I wish I could easily donate my tiny settlements to a good cause. It might make it worth the time to register for the class.

Re: Have I Been Pwned 2.0

#35
post #27

Earlier quoted context omitted.

> How does anyone fail at this in the modern era? Most probably some ancient legacy mainframe or whatnot other integration that nobody really has the time and budget to clean up and migrate to something more modern. The larger the company, the larger the risk for ossification of anything deemed "business critical" because even a minuscule outage of one hour now is six if not seven figures worth of "lost" time.

LinkedIn isn't old enough to have anything ancient. It was launched in 2003, and even then you'd get laughed at for suggesting storing passwords in plaintext.

Plaintext, sure, but it was certainly common still to use SHA-256 which is very quickly cracked if your password is short.

Re: Have I Been Pwned 2.0

#36
post #34
post #22

He should partner with a law firm, for class action lawsuits, for every breach due to negligence (which is probably all of them). Tie in to a banking service, so you can do direct deposits to many millions of people, every time there's new settlements paid, and you'll be a folk hero. Get lawyers who want negligent companies to actually regret the breaches, with judgements that hurt. (Rather than a small settlement th…

> do direct deposits to many millions of people, every time there's new settlements paid I wish I could easily donate my tiny settlements to a good cause. It might make it worth the time to register for the class.

I'd donate a bit to make this a reality if someone had a chance at pulling such a service off.

Re: Have I Been Pwned 2.0

#38
post #34
post #22

He should partner with a law firm, for class action lawsuits, for every breach due to negligence (which is probably all of them). Tie in to a banking service, so you can do direct deposits to many millions of people, every time there's new settlements paid, and you'll be a folk hero. Get lawyers who want negligent companies to actually regret the breaches, with judgements that hurt. (Rather than a small settlement th…

> do direct deposits to many millions of people, every time there's new settlements paid I wish I could easily donate my tiny settlements to a good cause. It might make it worth the time to register for the class.

Probably impossible, but create a slush fund where companies that behave badly are forced to pay into so we can do things like fix roads and build housing.

Re: Have I Been Pwned 2.0

#39
post #34

Earlier quoted context omitted.

> do direct deposits to many millions of people, every time there's new settlements paid I wish I could easily donate my tiny settlements to a good cause. It might make it worth the time to register for the class.

Probably impossible, but create a slush fund where companies that behave badly are forced to pay into so we can do things like fix roads and build housing.

Wow I think you just launched a political party I would vote for
Post reply on HN