Live data from Hacker News

Have I Been Pwned 2.0

troyhunt.com

291–300 of 323 posts

Re: Have I Been Pwned 2.0

#291

When it mentions that your password has been leaked for a service, is this the plain text pwd (that service somehow stored that way) or is it a hash? Was the website salting the passwords (so no rainbow-table attack could happen)? What key derivation function were they using? Etc... I feel the red circle with "Password compromised" is way too simplistic if this wants to be a TRUE trusty site regarding cybersecurity.…

I'm not convinced the target audience is infosec.

I've leveraged this site a few times to show family members the pervasiveness of breaches and to recommend pw managers.

If a tool like this can help a few people increase their posture then I consider it a success.

Re: Have I Been Pwned 2.0

#292

Does anyone else feel like the new design feels less trustworthy? I've probably just been conditioned on too many templates that all look the same, and there's nothing inherently wrong with it, yet it makes me wonder if I've accidentally opened a ripoff instead of the real thing.

It also has horrible performance and hikacks scroll. The site feels horrendous.

Re: Have I Been Pwned 2.0

#295

Earlier quoted context omitted.

Use multi-factor authentication and strong, unique passwords for everything and you'll never have to worry about this.

How exactly is that supposed to prevent your data from getting stolen in a database leak?

This thread isn't about data in general, only passwords. So first of all, a strong password is much harder to crack in the instance that it's stored in a hashed form in the database. In the instance it's stored (unforgivably) in cleartext, it cannot be used, because an additional factor is required to authenticate. That is how exactly.

Re: Have I Been Pwned 2.0

#296
post #254

Earlier quoted context omitted.

The US solution does not make users whole and does not meaningfully change anything. The EU solution meaningfully changes the offending company's behavior. I would rather have significantly less breaches of my information than a check for $6 in the mail every couple months.

> The EU solution meaningfully changes the offending company's behavior. Citation needed. I'd imagine they just add a tiny markup to their prices to pay the eventual fine instead of investing huge amounts of money into fixing their broken processes. Comparing the list of EU-issued fines against the respective companies' profits shows that they can simply afford to make those mistakes instead of preventing them.

Stock holders generally frown upon multi-billion euro fines and may want a change in management.

Re: Have I Been Pwned 2.0

#297
post #261

Earlier quoted context omitted.

The things he mentioned are of the same class, so yes, it does "extend the logic". Just because the name for something is confusing, that doesn't change the nature of the thing named.

They are not of the same class. The class is "job title", implying employment. "Regional director" is a job title. The others are not.

"Microsoft Regional Director" is not a job title. It is an award that Microsoft gives out only to non-employees.

You might think the award has a confusing name, and you would be correct. What you cannot be correct in asserting is that an award makes someone an employee because that award has a confusing name. That isn't a question of "semantics", if you assert that award makes him an employee, you are simply wrong.

Re: Have I Been Pwned 2.0

#298
post #276
post #261

Earlier quoted context omitted.

The things he mentioned are of the same class, so yes, it does "extend the logic". Just because the name for something is confusing, that doesn't change the nature of the thing named.

None of the things mentioned are common job titles, so no, they are not the same class.

"Microsoft Regional Director" is not a job title, it is an award. You thinking it sounds like a job title doesn't make it a job title, it makes you confused. Being given an award does not make you an employee, especially when that award is only given to non-employees.

You ar correct, "Microsoft Region Director" is an award, not a certification like the others mentioned so they aren't quite the same class, but the analogy still holds. Neither being given an award nor a certification makes you an employee.

Re: Have I Been Pwned 2.0

#299
post #209

Earlier quoted context omitted.

It's a sponsorship, so I'm not complaining, but if the goal was really to get people to use a password manager he would be sending them to Bitwarden since they have a free plan, plus their paid plan is only $10/year compared to $36 for 1Password.

Besides the pricing, is there any reason to prefer Bitwarden over 1Password? Been happily using 1Password for some years, never had any issues, but maybe I'm glossing over anything? Probably the cli interface (`op`) is the one feature I couldn't live without today.

They both do e2ee so they cannot read your secrets server-side, which is the standard.

Critically though, Bitwarden is open source, meaning that if the encryption is weakened, it would be noticed in the source.

With 1Password the clients are closed source: you have to trust the company to encrypt the secrets properly and an (malicious or accidental) change of the encryption cannot be detected by the user.

After Lastpass's fiasco around encryption, I don't feel like blindly trusting another company.

Re: Have I Been Pwned 2.0

#300

Earlier quoted context omitted.

> The EU solution meaningfully changes the offending company's behavior. Citation needed. I'd imagine they just add a tiny markup to their prices to pay the eventual fine instead of investing huge amounts of money into fixing their broken processes. Comparing the list of EU-issued fines against the respective companies' profits shows that they can simply afford to make those mistakes instead of preventing them.

Stock holders generally frown upon multi-billion euro fines and may want a change in management.

And it's probably securities fraud ;)
Post reply on HN