Live data from Hacker News

Have I Been Pwned 2.0

troyhunt.com

261–270 of 323 posts

Re: Have I Been Pwned 2.0

#261
post #244

Earlier quoted context omitted.

Its not semantics at all, you just are excusing your own misunderstanding. He didn't describe himself with a job title, and he even explicitly states directly after listing those awards, that he is not an employee of Microsoft. Extending your logic, I have a CCIE, so if I ever state I'm a CCIE, I'm an employee of Cisco? I have a masters degree by coursework from a university, so I I ever state I have an Msc, I'm an e…

All your examples are not things that commonly are job titles, so you are not "extending logic".

The things he mentioned are of the same class, so yes, it does "extend the logic".

Just because the name for something is confusing, that doesn't change the nature of the thing named.

Re: Have I Been Pwned 2.0

#262

Earlier quoted context omitted.

Its not semantics at all, you just are excusing your own misunderstanding. He didn't describe himself with a job title, and he even explicitly states directly after listing those awards, that he is not an employee of Microsoft. Extending your logic, I have a CCIE, so if I ever state I'm a CCIE, I'm an employee of Cisco? I have a masters degree by coursework from a university, so I I ever state I have an Msc, I'm an e…

Remind me what CCIE stands for? I don't think many people would be confused into thinking a Microsoft Certified Application Developer or an AWS Certified Cloud Practitioner are actually employees of those particular companies

Yes, those are better names. That doesn't make him a Microsoft employee.

Re: Have I Been Pwned 2.0

#264
What's the best service or app for tracking data breaches where your username and password are leaked? I'm trying to mitigate some leaks through ProtonPass but it's very frustrating as they simply say "password ****123 was found on the dark web" (they actually redact the full password) so then I manually have to go through my 100+ passwords and look for that particular password.

Re: Have I Been Pwned 2.0

#265
post #209

Earlier quoted context omitted.

Besides the pricing, is there any reason to prefer Bitwarden over 1Password? Been happily using 1Password for some years, never had any issues, but maybe I'm glossing over anything? Probably the cli interface (`op`) is the one feature I couldn't live without today.

Open-source versus proprietary and the option to self-host are the two that immediately come to mind.

I can't speak about the other password managers, but 1Password's architecture ensures even 1Password can't see any of your credentials. It's E2E Encrypted.

I've been a 1Password user for over a decade. It's user friendly, and I'd rather not have the responsibility to self-host my company and extended family's credentials.

Re: Have I Been Pwned 2.0

#266
post #22

He should partner with a law firm, for class action lawsuits, for every breach due to negligence (which is probably all of them). Tie in to a banking service, so you can do direct deposits to many millions of people, every time there's new settlements paid, and you'll be a folk hero. Get lawyers who want negligent companies to actually regret the breaches, with judgements that hurt. (Rather than a small settlement th…

Ah yes, automated lawsuit initiation, that's what we need! Ooh, we could run every breach announcement through Deep Research and let the AI make a determination on which one is negligence! That would definitely incentivize more transparency and accountability on behalf of companies!

Actually no, the end result of this will be a return to deny, deny, deny, because the worst case scenario then becomes the truth getting out.

IMHO we should be crucifying the liars and the truly negligent, but forgiving the honest and good faith efforts. At least for now, automating that judgment is pretty difficult and will result in more of the "customer service" like experiences that we already get from most big tech, except now it has the power to make or break companies.

Man we have sure moved on from the era of Blackstone's Ratio being a thing people united around. I'm not saying it should be applied literally, but punishing an innocent person should be considered a lot more wrong than not punishing a guilty person IMHO.

Re: Have I Been Pwned 2.0

#267
post #221

Earlier quoted context omitted.

Is your per-company addresses a derivation of your main email address? If so, this is called “email tumbling” and services exist to strip the “per-company” part to expose your main email.

I can't speak for OP but I too use per-company or per-service emails, and no they have zero connection to my main email (not even the domain actually, domains are cheap so I have multiple ones for different purposes). Since I started doing so a very long time ago I did choose a standard scheme for it (making use of the company's domain), so it would certainly be possible to recognize it's a per-company domain given h…

There was a while where I had a complex lookup system Apple got "strawberry.cake@example.com", and posting to mailing lists were sent from "steve@12.2025.example.com" - which would lose MX records after a month.

But in the end I settled on facebook@example.com, instagram@example.com, and similar obvious names.

Re: Have I Been Pwned 2.0

#268
post #261
post #244

Earlier quoted context omitted.

All your examples are not things that commonly are job titles, so you are not "extending logic".

The things he mentioned are of the same class, so yes, it does "extend the logic". Just because the name for something is confusing, that doesn't change the nature of the thing named.

They are not of the same class. The class is "job title", implying employment. "Regional director" is a job title. The others are not.

Re: Have I Been Pwned 2.0

#269
post #202

> It's likely a single-digit percentage of requests that are real humans being [blocked], and we need to look at ways to get that number down, but at least the fallback positions are improved now. The fallback suggestions mentioned in the article are "try clicking the box again" and "try reloading the page" I'm slowly starting to wonder if I should start sending snail mail to companies that block me, instead of resig…

6 hours later, case in point...

I'm blocked logging into Slack due to an invisible captcha: https://snipboard.io/h1E86S.jpg

I was surprised I was failing to type this code over from my email but no, that wasn't the issue. In the developer tools, the server fesses up I'm detected as "bot" again. As it's an invisible process, there's nothing I can do about it. This is a clean browser because it's for pentesting websites at work. No add-ons installed, no uBlock, no noscript, no corporate configuration, nothing

Re: Have I Been Pwned 2.0

#270

Earlier quoted context omitted.

I always picture a random middle manager in $large_organisation being told about something like this, and then they work out the angles and try to find the benefit. If the method works, and it shows that the logging feature Fred got so much credit for is storing passwords, what are the political implications of that? Can our intrepid middle manager steal some of Fred's glory? Or is Fred an ally and it should be caref…

The fact that you think random middle managers are all that psychopathic really says more about you than it does some hypothetical middle manager. Are their psychopaths and Machiavellian schemers in management? Certainly. Are they the majority? Almost certainly not, unless you're working for absolutely the wrong company. As the Brits would say, "cock-up before conspiracy."

No. It may not be conscious Machiavellian scheme, but it's a common attitude among middle managers. They are extremely sensitive to their reputation, which is why they punish people who make them look bad, even if it's something good for the company. Finding security vulnerabilities or wasted resources is met with an ambiguous hostility.

And unfortunately, a lot of people aren't emotionally intelligent enough to recognize that many managers use emotional reactions to redirect the room away from them. Because if you're the angry one, people won't ask questions like "didn't someone mention the possibility of this to you 6 months ago?"

Post reply on HN