Live data from Hacker News

Have I Been Pwned 2.0

troyhunt.com

191–200 of 323 posts

Re: Have I Been Pwned 2.0

#191
post #22

He should partner with a law firm, for class action lawsuits, for every breach due to negligence (which is probably all of them). Tie in to a banking service, so you can do direct deposits to many millions of people, every time there's new settlements paid, and you'll be a folk hero. Get lawyers who want negligent companies to actually regret the breaches, with judgements that hurt. (Rather than a small settlement th…

> Tie in to a banking service, so you can do direct deposits to many millions of people, every time there's new settlements paid, and you'll be a folk hero.

That's not much of a motivation, given that Troy already is a folk hero.

Re: Have I Been Pwned 2.0

#192

Does anyone feel like paying $274 and checking if the domains search allows gmail, hotmail etc? :o)

I signed up for domain search when it was still free. It requires verifying an email address that you shouldn't have access to, unless the email service in question is not set up according to RFCs.

Re: Have I Been Pwned 2.0

#193

Earlier quoted context omitted.

It's not a job title, it's some Microsoft program, like their MVP program. The RD site linked from Troy's site isn't loading for me at the moment, but if you search "what is the microsoft regional director program" you get back information making it clear that it's not for MS Employees. https://rd.microsoft.com/en-us/ > The Microsoft Regional Directors program recognizes industry professionals for their cross-platfor…

What a strange naming choice though...

You can be sure that the confusion is not accidental.

As I see it, it's a way for MS to profit from free labour for it's support service and a marketing stunt to benefit by association from the good reputation of this researcher and his initiative.

Even if it is not the case, people like the one previously will think: it is Microsoft employees that are managing this website, they know security.

Re: Have I Been Pwned 2.0

#194

Like many people I have a "main" email address, and I use per-company addresses for almost everything else. Now that the domain-searches require subscriptions this site has become much less useful. I just added my domain to the site again and I see "2,243 Total Breached Addresses", and "18 Addresses excluding Spam Lists", but I have no idea what they are. Attempting to click the links shows me I need to "upgrade" to…

I have quite a few personal catch-all domain names, and two of the main ones are used for the per website alias as you do, so over a decade and longer later, I would never be able to manually enter each address. Or remember them.

And yes, the subscribe restrictions for domain searches are annoying.

But Troy and family also need to eat, so I understand the need for a payment part, especially for companies.

We just ended up in the grey zone in between. I wish there were some more nuances, but then again, HIBP can't cater for every edge case unless they want to hire lots of devs and customer services.

I ended up signing up for a subscription, checked my domains, and then cancelled the subscription. It felt a little cumbersome, but ok. A non-recurring 2-day access would have worked for me...

Re: Have I Been Pwned 2.0

#195
I was always frustrated by this service because it is good to tell you that you have been pwned and your email appears in a breach but sadly it is more often than not more scary than useful as you can't see exactly what has been leaked about you. Especially your password.

I understand the rational to hide the details, but bad actors like criminal probably have the source file with the details anyway.

What annoys me is that it is good to know that your email appears in a random pastebin agglomerating hundreds of leaks but if they don't give the exact name and date of the site, and without seeing the password it is hard to know who leaked your data and which password to change.

The worse is that I was used to use a very shitty simple password for all the sites that ask one without needing one (let's say media with free subscription needed to read a single article, Free conference or online webinar), ... and these one are the best targets to have leaks despite them being totally harmless if you take care to not give your personal info inside.

Re: Have I Been Pwned 2.0

#196

I’ve never been able to figure out how haveibeenpwned.com can be useful to me, since I have had the same email address for many years and I don’t want to give it up. Do people get a new primary email address every time their address shows up in a breach list like haveibeenpwned ?

I used to have a primary email address as well (which occurs in several HIBP breaches). I never gave it up, I still have it to this day for sending personal mail. However, I started using service-specific email addresses (e.g. hackernews@example.org) at some point, gradually transitioning every account I registered somewhere to this new scheme. They all end up in the same inbox, together with the emails from the orig…

I do too. Though it does get awkward when dealing with a human related to that site. E.g. a small time hotel phoning about a booking or a local events organiser, they all seem weirded out that I have their name in my email address... :) I often rely on Fastmail's email masking these days instead, which at least reduces that human interaction awkwardness.

Re: Have I Been Pwned 2.0

#197
post #34
post #22

He should partner with a law firm, for class action lawsuits, for every breach due to negligence (which is probably all of them). Tie in to a banking service, so you can do direct deposits to many millions of people, every time there's new settlements paid, and you'll be a folk hero. Get lawyers who want negligent companies to actually regret the breaches, with judgements that hurt. (Rather than a small settlement th…

> do direct deposits to many millions of people, every time there's new settlements paid I wish I could easily donate my tiny settlements to a good cause. It might make it worth the time to register for the class.

[deleted]

Re: Have I Been Pwned 2.0

#198
post #186

Earlier quoted context omitted.

I don’t know about Belgium specifically, but one of the usual issues is that it incentivises aggressive policing of minor issues that make money (like parking violations), which takes resources out of other problems (like mugging).

In some situations ( cough random towns with sections of highway running through them in Texas), it incentivizes an approach to traffic enforcement which is barely distinguishable from getting mugged.

Putting the highway, into highway robbery!

Re: Have I Been Pwned 2.0

#200
post #149

Earlier quoted context omitted.

This is literally what happened in Belgium when politicians did budget. A piece of the expected slice was traffic fines. So that means that any kind of system that would improve traffic other than repressive measures would cost them twice, once to fix the situation and again when they can issue less fines.

If I drive carelessly and get a meaningful fine, I'll think twice next time, irrespective of who gets the money. I only care that I am fined. Unless the police starts to administer fines when they shouldn't, all is good, right? What happened in Belgium?

That's fine for you personally, and it may sound all good from a logical, theoretical, or academic perspective, however I personally know of people who have lost their license due to multiple fines and "demerit points" (NZ) resulting in that consequence.

The fines, and loss of license hurt them personally, professionally, and financially, but didn't change their behavior outside of the very short term.

In NZ we have people that are in and out of prison due to burglaries, robberies, etc... but the penalties don't change their longer term behavior.

There's a deeper problem, and penalties are important, but not the entire fix.

Post reply on HN