Live data from Hacker News

Have I Been Pwned 2.0

troyhunt.com

231–240 of 323 posts

Re: Have I Been Pwned 2.0

#232

Does it feel like this site is itself a vulnerability? It seems like being able to go type in anybody's email address and just get a list of sites where it was found would be part of an OSINT process. Shouldn't it at least send you a link to verify that you control the address before showing your results?

I felt the exact same way. Especially because I saw my email had been registered and leaked by some seedy looking conservative news site full of Trump propaganda. I always knew people could sign others up for junk "malicious subscriptions" and suspected that is what happened when I would get this trash in my inbox, but now seeing that other people can also see it very publicly is disturbing. How are they to know I didn't sign up for this myself? I'd hate to think people were thinking that about me.

EDIT: Seems like https://haveibeenpwned.com/OptOut does the trick.

Re: Have I Been Pwned 2.0

#233

Does it feel like this site is itself a vulnerability? It seems like being able to go type in anybody's email address and just get a list of sites where it was found would be part of an OSINT process. Shouldn't it at least send you a link to verify that you control the address before showing your results?

I guess the assumption is that bad actors have access to the data anyway so putting such verification process is not deterring any bad actor in any way

Re: Have I Been Pwned 2.0

#234
I keep wondering if its smart to just roll over an email address when it gets compromised, and limit your exposure, as well as force you to change your password while you're on every website ditching your former email.

I know some people use email tags, but maybe just rolling a new email might be better, followed by deleting unused dead accounts you will never use again.

Re: Have I Been Pwned 2.0

#235

Earlier quoted context omitted.

"Microsoft Regional Director" We can debate semantics but if you describe yourself with a job title attached to a company then I suggest that you have an association which looks rather like ... employment.

Its not semantics at all, you just are excusing your own misunderstanding. He didn't describe himself with a job title, and he even explicitly states directly after listing those awards, that he is not an employee of Microsoft. Extending your logic, I have a CCIE, so if I ever state I'm a CCIE, I'm an employee of Cisco? I have a masters degree by coursework from a university, so I I ever state I have an Msc, I'm an e…

Remind me what CCIE stands for?

I don't think many people would be confused into thinking a Microsoft Certified Application Developer or an AWS Certified Cloud Practitioner are actually employees of those particular companies

Re: Have I Been Pwned 2.0

#236

Does it feel like this site is itself a vulnerability? It seems like being able to go type in anybody's email address and just get a list of sites where it was found would be part of an OSINT process. Shouldn't it at least send you a link to verify that you control the address before showing your results?

This is indeed a part of an OSINT process. Always has been.

Re: Have I Been Pwned 2.0

#238
post #22

He should partner with a law firm, for class action lawsuits, for every breach due to negligence (which is probably all of them). Tie in to a banking service, so you can do direct deposits to many millions of people, every time there's new settlements paid, and you'll be a folk hero. Get lawyers who want negligent companies to actually regret the breaches, with judgements that hurt. (Rather than a small settlement th…

Heh, such an American response. Sue everyone and everything, lawyers gets paid. But at the end of day, nothing changes.

Meanwhile in EU, we have laws like NIS2, where if negligent in non-compliance. Fines are 10mil. EUR or 2% of global annual revenue. Eg.: If Apple gets $8bil. fine, yep that changes quite a lot I think. :)

Re: Have I Been Pwned 2.0

#239
post #60

Earlier quoted context omitted.

Probably impossible, but create a slush fund where companies that behave badly are forced to pay into so we can do things like fix roads and build housing.

The idea of fines as a revenue stream has never sat well with me. Fines are meant to be a disincentive. The ideal collection amount is zero. Treating them as a revenue stream creates a perverse incentive to enforce the penalty without disincentivizing the behavior.

> The ideal collection amount is zero.

I agree with the overal position. Though I believe optimizing to collect zero fines is a bad measure.

A fine can be a relatively just mechanism to show that actions have consequences. And even the best people will occasionally make honest mistakes, so they will just get a fine instead of being persecuted for minor offences.

If fines degrade to a revenue stream, it's an indication something else is off with the financial structure inside the government. At least around here fines don't go into some official's private accounts, but I can see how they might "help" an underfunded department. Thinking about it this way, maybe we should consider funneling fines into a separate pool of money. Though I am not sure what to do when the fines are used to fix damage caused by the action (e.g. ecological damage). Governing is hard :(

Re: Have I Been Pwned 2.0

#240

Earlier quoted context omitted.

That's fine for you personally, and it may sound all good from a logical, theoretical, or academic perspective, however I personally know of people who have lost their license due to multiple fines and "demerit points" (NZ) resulting in that consequence. The fines, and loss of license hurt them personally, professionally, and financially, but didn't change their behavior outside of the very short term. In NZ we have…

Then these people _obviously_ are not fit to drive a multi-ton killing machine at all and should have their license permanently revoked, when they had multiple chances for introspection.

And yet people drive with suspended licenses every day.
Post reply on HN