Live data from Hacker News

Have I Been Pwned 2.0

troyhunt.com

251–260 of 323 posts

Re: Have I Been Pwned 2.0

#251

Earlier quoted context omitted.

A company as big as LinkedIn should have bots continually accessing their site with unique generated passwords etc., and then be searching for those secrets in logging pipelines, bytes on disk, etc. to see where they get leaked. I know much smaller companies that do this. Yes, it's easy to fuck up. But a responsible company implements mitigations. And LinkedIn can absolutely afford to do much more.

I always picture a random middle manager in $large_organisation being told about something like this, and then they work out the angles and try to find the benefit. If the method works, and it shows that the logging feature Fred got so much credit for is storing passwords, what are the political implications of that? Can our intrepid middle manager steal some of Fred's glory? Or is Fred an ally and it should be caref…

The fact that you think random middle managers are all that psychopathic really says more about you than it does some hypothetical middle manager.

Are their psychopaths and Machiavellian schemers in management? Certainly. Are they the majority? Almost certainly not, unless you're working for absolutely the wrong company.

As the Brits would say, "cock-up before conspiracy."

Re: Have I Been Pwned 2.0

#253

When it mentions that your password has been leaked for a service, is this the plain text pwd (that service somehow stored that way) or is it a hash? Was the website salting the passwords (so no rainbow-table attack could happen)? What key derivation function were they using? Etc... I feel the red circle with "Password compromised" is way too simplistic if this wants to be a TRUE trusty site regarding cybersecurity.…

Every detailed blurb on the breach that I've seen says "Passwords stored as" and lets you know how they were encrypted.

Re: Have I Been Pwned 2.0

#254

Earlier quoted context omitted.

Heh, such an American response. Sue everyone and everything, lawyers gets paid. But at the end of day, nothing changes. Meanwhile in EU, we have laws like NIS2, where if negligent in non-compliance. Fines are 10mil. EUR or 2% of global annual revenue. Eg.: If Apple gets $8bil. fine, yep that changes quite a lot I think. :)

How does the EU solution make user's whole? At least with class actions, users get to see a few pennies. I'm not trying to make an argument against strong regulatory bodies. We need those for sure. It would just be nice if the users were compensated for the exploitation and abuse they're subjected to.

The US solution does not make users whole and does not meaningfully change anything.

The EU solution meaningfully changes the offending company's behavior. I would rather have significantly less breaches of my information than a check for $6 in the mail every couple months.

Re: Have I Been Pwned 2.0

#255
post #22

He should partner with a law firm, for class action lawsuits, for every breach due to negligence (which is probably all of them). Tie in to a banking service, so you can do direct deposits to many millions of people, every time there's new settlements paid, and you'll be a folk hero. Get lawyers who want negligent companies to actually regret the breaches, with judgements that hurt. (Rather than a small settlement th…

Heh, such an American response. Sue everyone and everything, lawyers gets paid. But at the end of day, nothing changes. Meanwhile in EU, we have laws like NIS2, where if negligent in non-compliance. Fines are 10mil. EUR or 2% of global annual revenue. Eg.: If Apple gets $8bil. fine, yep that changes quite a lot I think. :)

Agreed. It's unfortunate how litigious we are but it's the only language we speak apparently.

Re: Have I Been Pwned 2.0

#256
post #254

Earlier quoted context omitted.

How does the EU solution make user's whole? At least with class actions, users get to see a few pennies. I'm not trying to make an argument against strong regulatory bodies. We need those for sure. It would just be nice if the users were compensated for the exploitation and abuse they're subjected to.

The US solution does not make users whole and does not meaningfully change anything. The EU solution meaningfully changes the offending company's behavior. I would rather have significantly less breaches of my information than a check for $6 in the mail every couple months.

> The EU solution meaningfully changes the offending company's behavior.

Citation needed. I'd imagine they just add a tiny markup to their prices to pay the eventual fine instead of investing huge amounts of money into fixing their broken processes. Comparing the list of EU-issued fines against the respective companies' profits shows that they can simply afford to make those mistakes instead of preventing them.

Re: Have I Been Pwned 2.0

#257

Like many people I have a "main" email address, and I use per-company addresses for almost everything else. Now that the domain-searches require subscriptions this site has become much less useful. I just added my domain to the site again and I see "2,243 Total Breached Addresses", and "18 Addresses excluding Spam Lists", but I have no idea what they are. Attempting to click the links shows me I need to "upgrade" to…

Yeah, I also sit in this grey area. I think the maximum is 10 per domain or so, and last I checked, I'd had 11 or 12 leaked, so I can no longer see them. It's unfortunate though I don't know an easy solution that allows both people with per-site addresses to get free access, and also companies to be required to pay.

Re: Have I Been Pwned 2.0

#258

Earlier quoted context omitted.

Its not semantics at all, you just are excusing your own misunderstanding. He didn't describe himself with a job title, and he even explicitly states directly after listing those awards, that he is not an employee of Microsoft. Extending your logic, I have a CCIE, so if I ever state I'm a CCIE, I'm an employee of Cisco? I have a masters degree by coursework from a university, so I I ever state I have an Msc, I'm an e…

If I say "I'm a Cisco Regional Director" or "I'm a Walmart Regional Director" is you immediate though that I don't work for Cisco/Walmart?

Nobody is really disputing that Microsoft chose a confusing award name. However that name being confusing doesn't mean he is an employee or anything really like an employee.

Re: Have I Been Pwned 2.0

#259
post #254

Earlier quoted context omitted.

The US solution does not make users whole and does not meaningfully change anything. The EU solution meaningfully changes the offending company's behavior. I would rather have significantly less breaches of my information than a check for $6 in the mail every couple months.

> The EU solution meaningfully changes the offending company's behavior. Citation needed. I'd imagine they just add a tiny markup to their prices to pay the eventual fine instead of investing huge amounts of money into fixing their broken processes. Comparing the list of EU-issued fines against the respective companies' profits shows that they can simply afford to make those mistakes instead of preventing them.

> they just add a tiny markup to their prices to pay the eventual fine instead

Ironically, this counter-argument applies perfectly to the "US solution".

On the contrary, EU's huge fines have a better chance of being effective.

Re: Have I Been Pwned 2.0

#260

Earlier quoted context omitted.

"Microsoft Regional Director" We can debate semantics but if you describe yourself with a job title attached to a company then I suggest that you have an association which looks rather like ... employment.

Its not semantics at all, you just are excusing your own misunderstanding. He didn't describe himself with a job title, and he even explicitly states directly after listing those awards, that he is not an employee of Microsoft. Extending your logic, I have a CCIE, so if I ever state I'm a CCIE, I'm an employee of Cisco? I have a masters degree by coursework from a university, so I I ever state I have an Msc, I'm an e…

Directly adjacent to the post it says "Hi, I'm Troy Hunt, I write this blog, run "Have I Been Pwned" and am a Microsoft Regional Director and MVP who travels the world speaking at events and training technology professionals"

That reads to me like he's a Microsoft Employee. It's obviously important/significant enough to include it prominently on his website.

Post reply on HN