Live data from Hacker News

Have I Been Pwned 2.0

troyhunt.com

121–130 of 323 posts

Re: Have I Been Pwned 2.0

#121
post #3

Is there a term for this trend in web design, with defaulting to dark mode and having slick gradients everywhere?

I think GitHub kinda did it first on their desktop home page, but that has been out for years.

As someone who frequented a lot of video game-centric Invision Power Boards in the early 2000s, this is deeply insulting.

Re: Have I Been Pwned 2.0

#122

Earlier quoted context omitted.

"He should partner with a law firm" He is a Microsoft employee.

No, he's not. https://www.troyhunt.com/about/ says "I don't work for Microsoft"

"Microsoft Regional Director"

We can debate semantics but if you describe yourself with a job title attached to a company then I suggest that you have an association which looks rather like ... employment.

Re: Have I Been Pwned 2.0

#124
post #37

For those who would prefer to stay a little more under the radar, you can hide results from a search of your email appearing on this service. https://haveibeenpwned.com/OptOut

What if the opt out list gets pwned?

Re: Have I Been Pwned 2.0

#125
post #53
post #31

Who has the record for being in the most breaches? My main email seems to currently be in 40 breaches, earliest one in from June 2011 (HackForums, don't even remember what that is), and last one in September 2024 (FrenchCitizens, although I'm not French nor have I ever lived in France).

You’ve got me beat by 1. Congratulations

[flagged]

Re: Have I Been Pwned 2.0

#126

Amazing that even within the last decade a site as large as LinkedIn could be storing unsalted passwords. How does anyone fail at this in the modern era?

It's actually really easy to do unintentionally. For an intervening middleware, a password field in a JSON object is just like any other field in a JSON object. You may have some kind of logging / tracking / analytics somewhere that logs request bodies. You don't even have to engage in marketing shenanigans for that to be a problem, an abuse prevention system (which is definitely a necessity at their scale) is enough…

Would this be solved by providing the client with a (frequently rotated) public key to encrypt the password field specifically before submitting to the server, so that the only place it can be decrypted and stored is the authentication service at the very end of its journey through the network?

Re: Have I Been Pwned 2.0

#127
post #88
post #60

Earlier quoted context omitted.

The idea of fines as a revenue stream has never sat well with me. Fines are meant to be a disincentive. The ideal collection amount is zero. Treating them as a revenue stream creates a perverse incentive to enforce the penalty without disincentivizing the behavior.

If your ideal is a perfect society where everyone follows the all rules all the time you are going to be sorely disappointed. The ideal collection amount is the size of the fine multiplied by the actual occurrence of the offense. And that revenue should be strictly used for rehabilitative or restorative justice. For example, speeding fines should go to road improvements that deter speeding making roads safer. If no o…

> The ideal collection amount is the size of the fine multiplied by the actual occurrence of the offense.

I don't think that's a logically self-consistent idea. The "actual occurrence of the offense" is not an inevitable pre-existing fact, it exists downstream of the size of the fine and efficiency of enforcement. If you fine people 5% of their annual income for going 1 mph over the speed limit, and put more traffic enforcement on the road, fewer people are going to speed.

So to answer the question "what's the ideal collection amount", you have to consider what the costs (economic and social) of rule breaking behavior are, and trade those off with how much behavior can be modified by fines, as well as the costs of enforcement.

Furthermore, just taking the statement at face value, the only way to actually collect the size of the fine multiplied by the actual occurrence of the offense is to successfully fine 100% of offenders or fine some non-offenders, but even if this is possible it's almost certainly not the "ideal" amount of enforcement.

Re: Have I Been Pwned 2.0

#128
post #31

Who has the record for being in the most breaches? My main email seems to currently be in 40 breaches, earliest one in from June 2011 (HackForums, don't even remember what that is), and last one in September 2024 (FrenchCitizens, although I'm not French nor have I ever lived in France).

I'm almost there with you with 35. I checked both of most used emails, and they are at 35 and 32.

Re: Have I Been Pwned 2.0

#129
post #95
post #93

I really wish I could put in my domain name, I have so many aliases that it's basically impossible to search each one individually.

it's right there after the "The Domain Search Feature" heading. Verify ownership, then you get results

Curiously the domain I've been using for years now only shows up in 1 breach... am I really lucky or am I only getting partial results?

Re: Have I Been Pwned 2.0

#130

Earlier quoted context omitted.

Not only is not in order, I tried a few emails and in all of them I get a bunch of sites that I've never used. I wonder if it's fetching the wrong data?

I regularly have doppelgangers that sign up for services with my email address. I've been added to door/visitor notifications. I have received medical information for them. Retirement package info. A telecom internal tracker. A Doubleclick account for a while. Lessons for their children. Countless rewards accounts.

This has literally never happened to me... is your email address "go@away.com" or something?
Post reply on HN