Live data from Hacker News

Have I Been Pwned 2.0

troyhunt.com

171–180 of 323 posts

Re: Have I Been Pwned 2.0

#171

Amazing that even within the last decade a site as large as LinkedIn could be storing unsalted passwords. How does anyone fail at this in the modern era?

LinkedIn at one point were continually pressuring people into handing over their email credentials in the name of making it easy to find your contacts. So yeah, LinkedIn have never been exactly a bastion of IT Security.

They (and the users) have a very real use case for that, just like a contacts app needs all of that. The problem is not keeping it safe.

Re: Have I Been Pwned 2.0

#173
post #152

Unfortunately the new UI does not allow to search for leaked phone numbers anymore. The old did (e.g. could check for facebook phone number leak, see https://www.troyhunt.com/the-facebook-phone-numbers-are-now-... ). The new does not let it pass through the input field. Edit: it's also statet in the announcement: > Just one little thing first - we've dropped username and phone number search support from the website B…

The API still supports it so it should still be possible to implement a new solution for it.

The reasons for dropping the feature as outlined in the announcement seem very reasonable to me considering the larger implications.

Re: Have I Been Pwned 2.0

#174
i like the new design, but it feels that the "stats" like the cache hit ratio and edge locations won't matter to the vast majority of visitors, who are just trying to check for potential breaches.

on the other hand, they will be great for the api/business pages

Re: Have I Been Pwned 2.0

#175

Earlier quoted context omitted.

"Microsoft Regional Director" We can debate semantics but if you describe yourself with a job title attached to a company then I suggest that you have an association which looks rather like ... employment.

It's not a job title, it's some Microsoft program, like their MVP program. The RD site linked from Troy's site isn't loading for me at the moment, but if you search "what is the microsoft regional director program" you get back information making it clear that it's not for MS Employees. https://rd.microsoft.com/en-us/ > The Microsoft Regional Directors program recognizes industry professionals for their cross-platfor…

What a strange naming choice though...

Re: Have I Been Pwned 2.0

#177
post #63

Lots of regular people use Have I Been Pwned and sending them to 1Password is probably the single best thing you could do for them (I know it's a sponsorship - but it's a very complimentary one). I'd make the language around that promo banner stronger (ie. "We strongly recommend") and make it stand out more on the page. So many social media accounts get hacked[0] because of shared passwords and those affected users o…

It's a sponsorship, so I'm not complaining, but if the goal was really to get people to use a password manager he would be sending them to Bitwarden since they have a free plan, plus their paid plan is only $10/year compared to $36 for 1Password.

Re: Have I Been Pwned 2.0

#178

Earlier quoted context omitted.

It's actually really easy to do unintentionally. For an intervening middleware, a password field in a JSON object is just like any other field in a JSON object. You may have some kind of logging / tracking / analytics somewhere that logs request bodies. You don't even have to engage in marketing shenanigans for that to be a problem, an abuse prevention system (which is definitely a necessity at their scale) is enough…

A company as big as LinkedIn should have bots continually accessing their site with unique generated passwords etc., and then be searching for those secrets in logging pipelines, bytes on disk, etc. to see where they get leaked. I know much smaller companies that do this. Yes, it's easy to fuck up. But a responsible company implements mitigations. And LinkedIn can absolutely afford to do much more.

I always picture a random middle manager in $large_organisation being told about something like this, and then they work out the angles and try to find the benefit.

If the method works, and it shows that the logging feature Fred got so much credit for is storing passwords, what are the political implications of that? Can our intrepid middle manager steal some of Fred's glory? Or is Fred an ally and it should be carefully handled? Or do they sit on it and wait until an opportune moment to destroy Fred?

This is the kind of reasoning process I think goes on, because I've seen very few large organisations make actually-good technical decisions.

Re: Have I Been Pwned 2.0

#180
1) The search function has disappeared from the home page.

2) When clicking "details" on one of the search results, and then the back button, the search results disappear.

3) Other than that, thanks man great service!

Post reply on HN