Earlier quoted context omitted.
Governments should not operate fiscally like corporations. A financial institution will budget around fees because it's in their benefit for their customers to incur fees. A government should not budget around fines because they want the behavior which was fined to not occur at all.
I think one way to prevent bad incentives is to ensure that the organizational units that create and enforce policies are not the ones that benefit from any fines collected.
Have I Been Pwned 2.0
241–250 of 323 posts
Re: Have I Been Pwned 2.0
#242> It's likely a single-digit percentage of requests that are real humans being [blocked], and we need to look at ways to get that number down, but at least the fallback positions are improved now. The fallback suggestions mentioned in the article are "try clicking the box again" and "try reloading the page" I'm slowly starting to wonder if I should start sending snail mail to companies that block me, instead of resig…
Agreed, it seems like my (fixed) IP address is triggering Google and CF for some reason. I don't run any scrapers or so from home but do use NoScript, am I a bot for using NoScript? Perhaps.
Re: Have I Been Pwned 2.0
#243Does it feel like this site is itself a vulnerability? It seems like being able to go type in anybody's email address and just get a list of sites where it was found would be part of an OSINT process. Shouldn't it at least send you a link to verify that you control the address before showing your results?
I think it is a reasonable trade-off. For non-technical people (i.e. ~everyone) it provides a really useful service where you can see if your data has been leaked and what passwords to reset. For bad guys it makes their lives a little easier by creating a quick lookup and potentially knowledge about some leaks they weren't aware of, but ultimately there'd be a dark web version if HIBP didn't exist.
I think there's also a lot of PR value in a site like HIBP. If a non-technical person sees a headline like "400 million customer records leaked by Big Corp" it feels pretty abstract, but if you go and type your email address into HIBP and see a list of companies who have leaked your email address (and most likely some other data) it feels more personal.
Re: Have I Been Pwned 2.0
#244Earlier quoted context omitted.
"Microsoft Regional Director" We can debate semantics but if you describe yourself with a job title attached to a company then I suggest that you have an association which looks rather like ... employment.
Its not semantics at all, you just are excusing your own misunderstanding. He didn't describe himself with a job title, and he even explicitly states directly after listing those awards, that he is not an employee of Microsoft. Extending your logic, I have a CCIE, so if I ever state I'm a CCIE, I'm an employee of Cisco? I have a masters degree by coursework from a university, so I I ever state I have an Msc, I'm an e…
Re: Have I Been Pwned 2.0
#245I just verified that this database does not include the Vultr breach, or, at least it does not include email addresses that are unique to the Vultr service.
Re: Have I Been Pwned 2.0
#246Earlier quoted context omitted.
Makes me feel a little powerless. The only thing I can really do is freeze my credit
Use multi-factor authentication and strong, unique passwords for everything and you'll never have to worry about this.
Re: Have I Been Pwned 2.0
#247He should partner with a law firm, for class action lawsuits, for every breach due to negligence (which is probably all of them). Tie in to a banking service, so you can do direct deposits to many millions of people, every time there's new settlements paid, and you'll be a folk hero. Get lawyers who want negligent companies to actually regret the breaches, with judgements that hurt. (Rather than a small settlement th…
Heh, such an American response. Sue everyone and everything, lawyers gets paid. But at the end of day, nothing changes. Meanwhile in EU, we have laws like NIS2, where if negligent in non-compliance. Fines are 10mil. EUR or 2% of global annual revenue. Eg.: If Apple gets $8bil. fine, yep that changes quite a lot I think. :)
Re: Have I Been Pwned 2.0
#248Earlier quoted context omitted.
Probably impossible, but create a slush fund where companies that behave badly are forced to pay into so we can do things like fix roads and build housing.
We could also design some kind of electoral process for picking those in charge of defining the rules and creating yet more bodies to enforce it. Maybe this time we can come up with a better way to disincentivize corruption and bribery.
Re: Have I Been Pwned 2.0
#249Re: Have I Been Pwned 2.0
#250He should partner with a law firm, for class action lawsuits, for every breach due to negligence (which is probably all of them). Tie in to a banking service, so you can do direct deposits to many millions of people, every time there's new settlements paid, and you'll be a folk hero. Get lawyers who want negligent companies to actually regret the breaches, with judgements that hurt. (Rather than a small settlement th…
Heh, such an American response. Sue everyone and everything, lawyers gets paid. But at the end of day, nothing changes. Meanwhile in EU, we have laws like NIS2, where if negligent in non-compliance. Fines are 10mil. EUR or 2% of global annual revenue. Eg.: If Apple gets $8bil. fine, yep that changes quite a lot I think. :)
I'm not trying to make an argument against strong regulatory bodies. We need those for sure. It would just be nice if the users were compensated for the exploitation and abuse they're subjected to.