Live data from Hacker News

Have I Been Pwned 2.0

troyhunt.com

111–120 of 323 posts

Re: Have I Been Pwned 2.0

#111
post #31

Who has the record for being in the most breaches? My main email seems to currently be in 40 breaches, earliest one in from June 2011 (HackForums, don't even remember what that is), and last one in September 2024 (FrenchCitizens, although I'm not French nor have I ever lived in France).

HackForums is a popular skid forum ran by an FBI informant who lives in Vegas

Re: Have I Been Pwned 2.0

#112
post #22

He should partner with a law firm, for class action lawsuits, for every breach due to negligence (which is probably all of them). Tie in to a banking service, so you can do direct deposits to many millions of people, every time there's new settlements paid, and you'll be a folk hero. Get lawyers who want negligent companies to actually regret the breaches, with judgements that hurt. (Rather than a small settlement th…

"He should partner with a law firm" He is a Microsoft employee.

No, he's not.

https://www.troyhunt.com/about/ says "I don't work for Microsoft"

Re: Have I Been Pwned 2.0

#113

I’ve never been able to figure out how haveibeenpwned.com can be useful to me, since I have had the same email address for many years and I don’t want to give it up. Do people get a new primary email address every time their address shows up in a breach list like haveibeenpwned ?

They change their passwords...

Re: Have I Been Pwned 2.0

#114

I love this site! Though I do wonder how much this site also helps amateur hackers find where to search for a specific person's password. One way to deal with it could be to email the person their pwns.

As a security researcher who is into OSINT, HIBP is my first go to when obtaining an email address of interest. If it's found, it immediately helps me know which leaked DBs to go grep through and find more info about the target email addy.

Obtaining and storing TBs of leaked databases is another part of the puzzle that is always growing and a bit more complex.

Re: Have I Been Pwned 2.0

#115
post #22

He should partner with a law firm, for class action lawsuits, for every breach due to negligence (which is probably all of them). Tie in to a banking service, so you can do direct deposits to many millions of people, every time there's new settlements paid, and you'll be a folk hero. Get lawyers who want negligent companies to actually regret the breaches, with judgements that hurt. (Rather than a small settlement th…

"He should partner with a law firm" He is a Microsoft employee.

[deleted]

Re: Have I Been Pwned 2.0

#116

I’ve never been able to figure out how haveibeenpwned.com can be useful to me, since I have had the same email address for many years and I don’t want to give it up. Do people get a new primary email address every time their address shows up in a breach list like haveibeenpwned ?

For personal use: To know what services you use have been breached. You can then follow it up with ensuring you rotate the password on that site/service.

If they have other PII of yours, it's a heads up that scammers might target you and/or your family with that information.

For work use: To monitor which sites/services employees use with work email addresses, and use it as a reminder/re-enforcement that they should rotate credentials used on that service, and if they're reusing them at work - to change there, too.

Re: Have I Been Pwned 2.0

#117

Amazing that even within the last decade a site as large as LinkedIn could be storing unsalted passwords. How does anyone fail at this in the modern era?

LinkedIn at one point were continually pressuring people into handing over their email credentials in the name of making it easy to find your contacts.

So yeah, LinkedIn have never been exactly a bastion of IT Security.

Re: Have I Been Pwned 2.0

#118
post #37

For those who would prefer to stay a little more under the radar, you can hide results from a search of your email appearing on this service. https://haveibeenpwned.com/OptOut

Thanks for the info!

For anyone considering, here are the 3 opt-outions that appear after you email verify:

1. Just remove my email address from public search

No one using the public HIBP search feature will be able to see your email address in the results. You’ll still be able to search your own address through the notification service, which verifies that you control the email before showing any results. If your email is part of a domain monitored by someone else (e.g., your employer), the domain controller will still be able to see it in domain-level searches.

2. Remove my email address from public search and delete the list of breaches it appears in

Your email address is no longer searchable — neither through the public service nor by you, even if you verify ownership — because the associated breaches have been deleted from the database. However, your email address is still retained by HIBP to ensure it is excluded from any future breaches and not added to your record.

3. Delete my email address completely

The record containing your email address will be completely deleted, meaning it will no longer appear in search results — for you or the public — at the time of deletion. However, if your email address appears in future data breaches, it will become publicly searchable again, as the opt-out record itself has also been deleted.

Re: Have I Been Pwned 2.0

#119

It shows you a vertically scrolling timeline (with logos and blurbs) of all the data breaches that have exposed your email. How delightfully horrifying.

Makes me feel a little powerless. The only thing I can really do is freeze my credit

Use multi-factor authentication and strong, unique passwords for everything and you'll never have to worry about this.
Post reply on HN