Live data from Hacker News

Have I Been Pwned 2.0

troyhunt.com

161–170 of 323 posts

Re: Have I Been Pwned 2.0

#161
post #47

Earlier quoted context omitted.

For all the talk of AI Slop, I don’t hear much about the fact that we have been suffering from Outsourced Slop for decades now. I suspect that is how this kind of thing also fail at LinkedIn. I say that based on my experience dealing with outsourcing companies and the product they produce through outsourced programmers. It’s really just been a similar problem as with AI code, that without strong and competent managem…

I'm on board with the cheap offshore and bad incentives motiv, but feel this has to be augmented with a mention of the senior cowboy coder (who just went into retirement). Most likely in the future these stereotypes will be joined by vibe coders and AI-powered juniors, but as someone working this industry for a couple of decades give or take - we've learned how to deal with these by now.

> the senior cowboy coder (who just went into retirement)

They just went into retirement?

Re: Have I Been Pwned 2.0

#162

Earlier quoted context omitted.

It's actually really easy to do unintentionally. For an intervening middleware, a password field in a JSON object is just like any other field in a JSON object. You may have some kind of logging / tracking / analytics somewhere that logs request bodies. You don't even have to engage in marketing shenanigans for that to be a problem, an abuse prevention system (which is definitely a necessity at their scale) is enough…

Would this be solved by providing the client with a (frequently rotated) public key to encrypt the password field specifically before submitting to the server, so that the only place it can be decrypted and stored is the authentication service at the very end of its journey through the network?

The existing solution for this is SRP (Secure Remote Passwords http://srp.stanford.edu/).

Unfortunately my understanding is that it’s trivial to implement unsoundly but it’s also not something for which there are an abundance of good implementations across languages.

It’s been awhile since I’ve looked though so maybe there is a newer, less radioactive approach. But yes, never actually sending the authenticator itself (and doing so in a way that the proof is valid only once) would stop this sort of thing cold.

Re: Have I Been Pwned 2.0

#163
post #140

I’ve never been able to figure out how haveibeenpwned.com can be useful to me, since I have had the same email address for many years and I don’t want to give it up. Do people get a new primary email address every time their address shows up in a breach list like haveibeenpwned ?

I have my own mail server and setup a catch all alias to a single account. So I can generate -- on the fly -- e-mails for services. - Apple: me.apple@example.com - Google: me.google@example.com - Uber: me.uber@example.com - Tinder: me.tinder@example.com - random business: me.randombusinessname@example.com This helps me with the following: - unique usernames and passwords for each service - easily able to tell when a…

If you use this approach, once 10 of your aliases are in the HIBP database you will need to pay for a subscription to see breaches for your domain (and even then the $40/year tier is only good for 25 aliases).

I wish HIBP had a solution for those of us who are individuals but use a domain catchall to manage online accounts.

Re: Have I Been Pwned 2.0

#164
Like many people I have a "main" email address, and I use per-company addresses for almost everything else. Now that the domain-searches require subscriptions this site has become much less useful.

I just added my domain to the site again and I see "2,243 Total Breached Addresses", and "18 Addresses excluding Spam Lists", but I have no idea what they are. Attempting to click the links shows me I need to "upgrade" to see them, and the download of excel and JSON result in 404 errors.

Too bad, I guess if you have only a single email address it might be good to get informed, but if you use a domain with multiple addresses it's way less useful.

Re: Have I Been Pwned 2.0

#165
post #103

Earlier quoted context omitted.

Ahh I see it on the footer of the website, a bit hidden! I'm not sure I really need it for personal use, more just a cool thing to see, so I'm a bit undecided on paying for the domain feature. I can see it being useful for a business though where each email is a different employee dealing with accounts everywhere.

You can pay for just one month at a time. I pay now and then and check in on my personal domain – like you, I use dozens of email addresses with a catchall.

The first tier ($4/month) only works for up to 25 aliases. Depending on how many of your aliases have leaked, you may have to pay a lot to perform that check.

I wish HIBP had a solution for those of us who are individuals but use domain catchall forwarding as our method for separating accounts.

It feels good to see adobe@mydomain.com, newrelic@mydomain.com, internetarchive@mydomain.com, etc. there but not any of the addresses I use for normal communication.

Re: Have I Been Pwned 2.0

#166
post #140

Earlier quoted context omitted.

I have my own mail server and setup a catch all alias to a single account. So I can generate -- on the fly -- e-mails for services. - Apple: me.apple@example.com - Google: me.google@example.com - Uber: me.uber@example.com - Tinder: me.tinder@example.com - random business: me.randombusinessname@example.com This helps me with the following: - unique usernames and passwords for each service - easily able to tell when a…

If you use this approach, once 10 of your aliases are in the HIBP database you will need to pay for a subscription to see breaches for your domain (and even then the $40/year tier is only good for 25 aliases). I wish HIBP had a solution for those of us who are individuals but use a domain catchall to manage online accounts.

Yes it really does suck - apparently I've been breached numerous times but I can't see details without paying.

Re: Have I Been Pwned 2.0

#167

I’ve never been able to figure out how haveibeenpwned.com can be useful to me, since I have had the same email address for many years and I don’t want to give it up. Do people get a new primary email address every time their address shows up in a breach list like haveibeenpwned ?

Your identity isn't a problem! Its the password bit.

Until it is

https://en.wikipedia.org/wiki/Ashley_Madison_data_breach

Using different random email aliases for each service is as much best practice as is different random passwords.

Re: Have I Been Pwned 2.0

#168
post #149

Earlier quoted context omitted.

This is literally what happened in Belgium when politicians did budget. A piece of the expected slice was traffic fines. So that means that any kind of system that would improve traffic other than repressive measures would cost them twice, once to fix the situation and again when they can issue less fines.

If I drive carelessly and get a meaningful fine, I'll think twice next time, irrespective of who gets the money. I only care that I am fined. Unless the police starts to administer fines when they shouldn't, all is good, right? What happened in Belgium?

If they design the road to make it harder to follow the rules it is bad.

Re: Have I Been Pwned 2.0

#169
post #63

Lots of regular people use Have I Been Pwned and sending them to 1Password is probably the single best thing you could do for them (I know it's a sponsorship - but it's a very complimentary one). I'd make the language around that promo banner stronger (ie. "We strongly recommend") and make it stand out more on the page. So many social media accounts get hacked[0] because of shared passwords and those affected users o…

Why not bitwarden?

Re: Have I Been Pwned 2.0

#170
post #83

Earlier quoted context omitted.

I think the problem is: 1. How else would you penalize businesses? 2. What else would you do with fines? If fines exist, it would seem foolish not to budget around that.

Governments should not operate fiscally like corporations. A financial institution will budget around fees because it's in their benefit for their customers to incur fees. A government should not budget around fines because they want the behavior which was fined to not occur at all.

I think one way to prevent bad incentives is to ensure that the organizational units that create and enforce policies are not the ones that benefit from any fines collected.
Post reply on HN