Live data from Hacker News

Have I Been Pwned 2.0

troyhunt.com

181–190 of 323 posts

Re: Have I Been Pwned 2.0

#182
post #171

Earlier quoted context omitted.

LinkedIn at one point were continually pressuring people into handing over their email credentials in the name of making it easy to find your contacts. So yeah, LinkedIn have never been exactly a bastion of IT Security.

They (and the users) have a very real use case for that, just like a contacts app needs all of that. The problem is not keeping it safe.

No user ever had a real use case for seeing a button that says "invite X" that doesn't send an invite on the platform, but instead sends an email to X who doesn't have a Linkedin account.

And if you decline, it asks you again. Two times using different wording.

Re: Have I Been Pwned 2.0

#183

Does anyone else feel like the new design feels less trustworthy? I've probably just been conditioned on too many templates that all look the same, and there's nothing inherently wrong with it, yet it makes me wonder if I've accidentally opened a ripoff instead of the real thing.

Yes. Maybe I'm just a grumpy old man, but I think website redesigns are just a marketing thing (and fun for web developers) and rarely benefit the user. Nasa ADS has a fantastic (if super old-looking) site for many years that was clean and fast and did the job, they spent a lot of time and effort jazzing it up with pictures and javascript, and now it still just does the same thing.

Re: Have I Been Pwned 2.0

#184

New HIBP, same old restriction banning users from 3rd world countries https://imgur.com/a/AzNSreV

"Have I been pwned... at birth, by accidents of geography and economics"

Sorry that's happened to you. The only remedy I can think of is get a non-commercial proxy in some "recommended" country like through a friend.

Re: Have I Been Pwned 2.0

#185
post #151

The ';-- in front of Pwned is a brilliant idea but less brilliant execution. Missed opportunity, I'm wondering how many people don't realize what it is

Oh that's what it was! I actually didn't think much of it until you pointed it out. At a glance looked like some random arrangement of squares

Re: Have I Been Pwned 2.0

#186
post #149

Earlier quoted context omitted.

If I drive carelessly and get a meaningful fine, I'll think twice next time, irrespective of who gets the money. I only care that I am fined. Unless the police starts to administer fines when they shouldn't, all is good, right? What happened in Belgium?

I don’t know about Belgium specifically, but one of the usual issues is that it incentivises aggressive policing of minor issues that make money (like parking violations), which takes resources out of other problems (like mugging).

In some situations (cough random towns with sections of highway running through them in Texas), it incentivizes an approach to traffic enforcement which is barely distinguishable from getting mugged.

Re: Have I Been Pwned 2.0

#187
post #22

He should partner with a law firm, for class action lawsuits, for every breach due to negligence (which is probably all of them). Tie in to a banking service, so you can do direct deposits to many millions of people, every time there's new settlements paid, and you'll be a folk hero. Get lawyers who want negligent companies to actually regret the breaches, with judgements that hurt. (Rather than a small settlement th…

That's a massive infrastructure change to pay out what would likely be peanuts to users, put a massive maintenance burden on the platform (payments are a nightmare system), and disproportionately benefit a law firm profiting off of the lawsuits and the good will of the brand. Seems like a shit deal to me.

Re: Have I Been Pwned 2.0

#188
post #37

For those who would prefer to stay a little more under the radar, you can hide results from a search of your email appearing on this service. https://haveibeenpwned.com/OptOut

What if the opt out list gets pwned?

I think there was an earlier blog post from Troy sometime ago describing that HIBP never stores unencrypted email addresses; i.e. they are all hashed and any lookups go against the hash, not the actual email address.

Re: Have I Been Pwned 2.0

#189
post #31

Who has the record for being in the most breaches? My main email seems to currently be in 40 breaches, earliest one in from June 2011 (HackForums, don't even remember what that is), and last one in September 2024 (FrenchCitizens, although I'm not French nor have I ever lived in France).

example@example.org is at 65 breaches. Fun!

Re: Have I Been Pwned 2.0

#190

I’ve never been able to figure out how haveibeenpwned.com can be useful to me, since I have had the same email address for many years and I don’t want to give it up. Do people get a new primary email address every time their address shows up in a breach list like haveibeenpwned ?

I used to have a primary email address as well (which occurs in several HIBP breaches). I never gave it up, I still have it to this day for sending personal mail. However, I started using service-specific email addresses (e.g. hackernews@example.org) at some point, gradually transitioning every account I registered somewhere to this new scheme. They all end up in the same inbox, together with the emails from the original address. If one of them ends up in a breach, I block delivery to that service-specific address and add a new one.
Post reply on HN