Live data from Hacker News

Have I Been Pwned 2.0

troyhunt.com

241–250 of 323 posts

Re: Have I Been Pwned 2.0

#241
post #170
post #83

Earlier quoted context omitted.

Governments should not operate fiscally like corporations. A financial institution will budget around fees because it's in their benefit for their customers to incur fees. A government should not budget around fines because they want the behavior which was fined to not occur at all.

I think one way to prevent bad incentives is to ensure that the organizational units that create and enforce policies are not the ones that benefit from any fines collected.

On the surface this sounds great, but governmental organizational units are still able to pressure one another, or have third parties apply pressure.

Re: Have I Been Pwned 2.0

#242
post #202

> It's likely a single-digit percentage of requests that are real humans being [blocked], and we need to look at ways to get that number down, but at least the fallback positions are improved now. The fallback suggestions mentioned in the article are "try clicking the box again" and "try reloading the page" I'm slowly starting to wonder if I should start sending snail mail to companies that block me, instead of resig…

Agreed, it seems like my (fixed) IP address is triggering Google and CF for some reason. I don't run any scrapers or so from home but do use NoScript, am I a bot for using NoScript? Perhaps.

Yeah, I have rather aggressive blocking on with uBlock Origin. Google started blocking me about a month ago, I have to solve captcha for literally every query. I know it's uBlock as things are back to normal when I disable it. Well, this helps me to learn new muscle memory to rely on DuckDuckGo and Brave Search instead.

Re: Have I Been Pwned 2.0

#243

Does it feel like this site is itself a vulnerability? It seems like being able to go type in anybody's email address and just get a list of sites where it was found would be part of an OSINT process. Shouldn't it at least send you a link to verify that you control the address before showing your results?

> Does it feel like this site is itself a vulnerability? It seems like being able to go type in anybody's email address and just get a list of sites where it was found would be part of an OSINT process.

I think it is a reasonable trade-off. For non-technical people (i.e. ~everyone) it provides a really useful service where you can see if your data has been leaked and what passwords to reset. For bad guys it makes their lives a little easier by creating a quick lookup and potentially knowledge about some leaks they weren't aware of, but ultimately there'd be a dark web version if HIBP didn't exist.

I think there's also a lot of PR value in a site like HIBP. If a non-technical person sees a headline like "400 million customer records leaked by Big Corp" it feels pretty abstract, but if you go and type your email address into HIBP and see a list of companies who have leaked your email address (and most likely some other data) it feels more personal.

Re: Have I Been Pwned 2.0

#244

Earlier quoted context omitted.

"Microsoft Regional Director" We can debate semantics but if you describe yourself with a job title attached to a company then I suggest that you have an association which looks rather like ... employment.

Its not semantics at all, you just are excusing your own misunderstanding. He didn't describe himself with a job title, and he even explicitly states directly after listing those awards, that he is not an employee of Microsoft. Extending your logic, I have a CCIE, so if I ever state I'm a CCIE, I'm an employee of Cisco? I have a masters degree by coursework from a university, so I I ever state I have an Msc, I'm an e…

All your examples are not things that commonly are job titles, so you are not "extending logic".

Re: Have I Been Pwned 2.0

#245

I just verified that this database does not include the Vultr breach, or, at least it does not include email addresses that are unique to the Vultr service.

Geez, and they have one of my domains with an address claiming to have been compromised by "B2B USA Businesses" in a leak in mid-2017, which is over a year before the domain was registered.

Re: Have I Been Pwned 2.0

#246

Earlier quoted context omitted.

Makes me feel a little powerless. The only thing I can really do is freeze my credit

Use multi-factor authentication and strong, unique passwords for everything and you'll never have to worry about this.

How exactly is that supposed to prevent your data from getting stolen in a database leak?

Re: Have I Been Pwned 2.0

#247
post #22

He should partner with a law firm, for class action lawsuits, for every breach due to negligence (which is probably all of them). Tie in to a banking service, so you can do direct deposits to many millions of people, every time there's new settlements paid, and you'll be a folk hero. Get lawyers who want negligent companies to actually regret the breaches, with judgements that hurt. (Rather than a small settlement th…

Heh, such an American response. Sue everyone and everything, lawyers gets paid. But at the end of day, nothing changes. Meanwhile in EU, we have laws like NIS2, where if negligent in non-compliance. Fines are 10mil. EUR or 2% of global annual revenue. Eg.: If Apple gets $8bil. fine, yep that changes quite a lot I think. :)

The difference between the US and the EU being: the cost of negligence is known ahead of time?

Re: Have I Been Pwned 2.0

#248

Earlier quoted context omitted.

Probably impossible, but create a slush fund where companies that behave badly are forced to pay into so we can do things like fix roads and build housing.

We could also design some kind of electoral process for picking those in charge of defining the rules and creating yet more bodies to enforce it. Maybe this time we can come up with a better way to disincentivize corruption and bribery.

I think there’s already an amendment for that.

Re: Have I Been Pwned 2.0

#250
post #22

He should partner with a law firm, for class action lawsuits, for every breach due to negligence (which is probably all of them). Tie in to a banking service, so you can do direct deposits to many millions of people, every time there's new settlements paid, and you'll be a folk hero. Get lawyers who want negligent companies to actually regret the breaches, with judgements that hurt. (Rather than a small settlement th…

Heh, such an American response. Sue everyone and everything, lawyers gets paid. But at the end of day, nothing changes. Meanwhile in EU, we have laws like NIS2, where if negligent in non-compliance. Fines are 10mil. EUR or 2% of global annual revenue. Eg.: If Apple gets $8bil. fine, yep that changes quite a lot I think. :)

How does the EU solution make user's whole? At least with class actions, users get to see a few pennies.

I'm not trying to make an argument against strong regulatory bodies. We need those for sure. It would just be nice if the users were compensated for the exploitation and abuse they're subjected to.

Post reply on HN