Live data from Hacker News

Have I Been Pwned 2.0

troyhunt.com

41–50 of 323 posts

Re: Have I Been Pwned 2.0

#41

A lot of companies I've never heard of before are leaking my data. :( Can we make it so that companies I've never heard of before don't have my data in the first place?

My latest one was from these guys https://www.eye4fraud.com/ who I have never knowingly done business with. Almost too absurd to be true

Re: Have I Been Pwned 2.0

#44

Earlier quoted context omitted.

Probably impossible, but create a slush fund where companies that behave badly are forced to pay into so we can do things like fix roads and build housing.

Wow I think you just launched a political party I would vote for

Fine companies to fund bridges.

Re: Have I Been Pwned 2.0

#45
post #27

Earlier quoted context omitted.

> How does anyone fail at this in the modern era? Most probably some ancient legacy mainframe or whatnot other integration that nobody really has the time and budget to clean up and migrate to something more modern. The larger the company, the larger the risk for ossification of anything deemed "business critical" because even a minuscule outage of one hour now is six if not seven figures worth of "lost" time.

LinkedIn isn't old enough to have anything ancient. It was launched in 2003, and even then you'd get laughed at for suggesting storing passwords in plaintext.

Doesn't mean that the infra is still ancient. What I see a lot is tech debt from migrations. Lots of times both the old and new systems have to work together for a period of time, so you leave certain legacy protocols and flags in place for the transition period and then the new system is never fully "updated" to the new standards. Pre win2k AD, file path lengths, encryption protocols, etc etc. Sure, the new system is "up to date" but the old compatibility settings remain.

Re: Have I Been Pwned 2.0

#47

Amazing that even within the last decade a site as large as LinkedIn could be storing unsalted passwords. How does anyone fail at this in the modern era?

For all the talk of AI Slop, I don’t hear much about the fact that we have been suffering from Outsourced Slop for decades now. I suspect that is how this kind of thing also fail at LinkedIn. I say that based on my experience dealing with outsourcing companies and the product they produce through outsourced programmers.

It’s really just been a similar problem as with AI code, that without strong and competent management that can set intelligent expectations and requirements and test for them, you will surely get what appears to all the business and leadership types like an equivalent product, without any sense that it’s slop underneath the surface.

Re: Have I Been Pwned 2.0

#48
post #3

Is there a term for this trend in web design, with defaulting to dark mode and having slick gradients everywhere?

It was first popularized by Linear https://medium.com/design-bootcamp/the-rise-of-linear-style-...

Not sure which was first, but I associate this style a lot with Apple's product pages like https://www.apple.com/au/macbook-pro/

Re: Have I Been Pwned 2.0

#50

> But now it's on a timeline you can scroll through in reverse chronological order, with each breach summarising what happened. Maybe I'm reading it wrong but it looks like it might be a little off. I get: - October 2013 - June 2008 - ...a bunch more... - November 2021 - December 2020

Not only is not in order, I tried a few emails and in all of them I get a bunch of sites that I've never used. I wonder if it's fetching the wrong data?

I regularly have doppelgangers that sign up for services with my email address.

I've been added to door/visitor notifications. I have received medical information for them. Retirement package info. A telecom internal tracker. A Doubleclick account for a while. Lessons for their children. Countless rewards accounts.

Post reply on HN