Live data from Hacker News

Have I Been Pwned 2.0

troyhunt.com

71–80 of 323 posts

Re: Have I Been Pwned 2.0

#71
post #69
post #60

Earlier quoted context omitted.

The idea of fines as a revenue stream has never sat well with me. Fines are meant to be a disincentive. The ideal collection amount is zero. Treating them as a revenue stream creates a perverse incentive to enforce the penalty without disincentivizing the behavior.

[deleted]

[deleted]

Re: Have I Been Pwned 2.0

#73
post #55
post #44

Earlier quoted context omitted.

Fine companies to fund bridges.

That sounds like a great slogan, but you really don't want a justice system that's has an additional mandate to collect revenue. It's basically civil forfeiture all over again

Isn't that...taxation? Seems alright to me!

Re: Have I Been Pwned 2.0

#74
post #60

Earlier quoted context omitted.

Probably impossible, but create a slush fund where companies that behave badly are forced to pay into so we can do things like fix roads and build housing.

The idea of fines as a revenue stream has never sat well with me. Fines are meant to be a disincentive. The ideal collection amount is zero. Treating them as a revenue stream creates a perverse incentive to enforce the penalty without disincentivizing the behavior.

Just like police departments use asset forfeiture to get money to buy their “toys” while innocent people lose their cash and cars because carrying cash is suspicious.

Re: Have I Been Pwned 2.0

#75
post #60

Earlier quoted context omitted.

Probably impossible, but create a slush fund where companies that behave badly are forced to pay into so we can do things like fix roads and build housing.

The idea of fines as a revenue stream has never sat well with me. Fines are meant to be a disincentive. The ideal collection amount is zero. Treating them as a revenue stream creates a perverse incentive to enforce the penalty without disincentivizing the behavior.

I think the problem is:

1. How else would you penalize businesses?

2. What else would you do with fines?

If fines exist, it would seem foolish not to budget around that.

Re: Have I Been Pwned 2.0

#76
post #60

Earlier quoted context omitted.

Probably impossible, but create a slush fund where companies that behave badly are forced to pay into so we can do things like fix roads and build housing.

The idea of fines as a revenue stream has never sat well with me. Fines are meant to be a disincentive. The ideal collection amount is zero. Treating them as a revenue stream creates a perverse incentive to enforce the penalty without disincentivizing the behavior.

This is literally what happened in Belgium when politicians did budget. A piece of the expected slice was traffic fines.

So that means that any kind of system that would improve traffic other than repressive measures would cost them twice, once to fix the situation and again when they can issue less fines.

Re: Have I Been Pwned 2.0

#77
post #55

Earlier quoted context omitted.

That sounds like a great slogan, but you really don't want a justice system that's has an additional mandate to collect revenue. It's basically civil forfeiture all over again

Isn't that...taxation? Seems alright to me!

fines ≠ taxes

Re: Have I Been Pwned 2.0

#78

Earlier quoted context omitted.

It's actually really easy to do unintentionally. For an intervening middleware, a password field in a JSON object is just like any other field in a JSON object. You may have some kind of logging / tracking / analytics somewhere that logs request bodies. You don't even have to engage in marketing shenanigans for that to be a problem, an abuse prevention system (which is definitely a necessity at their scale) is enough…

A company as big as LinkedIn should have bots continually accessing their site with unique generated passwords etc., and then be searching for those secrets in logging pipelines, bytes on disk, etc. to see where they get leaked. I know much smaller companies that do this. Yes, it's easy to fuck up. But a responsible company implements mitigations. And LinkedIn can absolutely afford to do much more.

that would require hiring a security personnel which they can't afford to do. /s

Re: Have I Been Pwned 2.0

#79
post #22

He should partner with a law firm, for class action lawsuits, for every breach due to negligence (which is probably all of them). Tie in to a banking service, so you can do direct deposits to many millions of people, every time there's new settlements paid, and you'll be a folk hero. Get lawyers who want negligent companies to actually regret the breaches, with judgements that hurt. (Rather than a small settlement th…

>Tie in to a banking service, so you can do direct deposits to many millions of people, every time there's new settlements paid, and you'll be a folk hero.

and how long until that data is breached?

Re: Have I Been Pwned 2.0

#80
I love this site! Though I do wonder how much this site also helps amateur hackers find where to search for a specific person's password. One way to deal with it could be to email the person their pwns.
Post reply on HN