Live data from Hacker News

Have I Been Pwned 2.0

troyhunt.com

311–320 of 323 posts

Re: Have I Been Pwned 2.0

#311

Earlier quoted context omitted.

Why do you feel it’s foolish that you used your own domain name?

I think OP means that they used aaa+facebook@smthg.com, so aaa@smthg.com is now revealed to be their main address. As opposed of having facebook@smthg.com only

I did it like the first one first then moved to the second, where @smthg.com is my domain, but it also has my name in it so it seemed counterintuitive to link my name to it.

Re: Have I Been Pwned 2.0

#312
post #311

Earlier quoted context omitted.

I think OP means that they used aaa+facebook@smthg.com, so aaa@smthg.com is now revealed to be their main address. As opposed of having facebook@smthg.com only

I did it like the first one first then moved to the second, where @smthg.com is my domain, but it also has my name in it so it seemed counterintuitive to link my name to it.

ah ok, thanks for the clarification this is a common problem with domains with actual names

Re: Have I Been Pwned 2.0

#313

Earlier quoted context omitted.

What if the opt out list gets pwned?

I assume if that ever happens, someone will register https://haveibeenpwnedbyhaveibeenpwned.com . It'll be the top post of HN for a couple of says while everyone argues in the comments about how the state of online security is "fundamentally broken" while someone asks if they can sue. Then we'll all forget and move on.

I'm surprised Troy Hunt hasn't defensively registered this. Compare https://troyhuntsucks.com/

Re: Have I Been Pwned 2.0

#314
post #262

Earlier quoted context omitted.

Yes, those are better names. That doesn't make him a Microsoft employee.

I'm not saying it makes him an employee. I'm saying those are bad attempts to argue that it's not a confusing title.

> I'm saying those are bad attempts to argue that it's not a confusing title.

You might want to reread, nobody was arguing that.

> We can debate semantics but if you describe yourself with a job title attached to a company then I suggest that you have an association which looks rather like ... employment.

"Debating semantics" is arguing about which definition to use. There is no valid definition under which you can say that Troy is a Microsoft employee.

You can't say "I'm not wrong, You're just debating semantics", all you can say is "I was wrong because I was confused by a misleading title I wasn't familiar with."

cupofnotjoe pointed this out and got a bunch of responses from people with poor reading comprehension who entirely missed his point.

Edit: I use 'you' in the general sense here, not specifically the person I'm responding to.

Re: Have I Been Pwned 2.0

#315
post #297

Earlier quoted context omitted.

"Microsoft Regional Director" is not a job title. It is an award that Microsoft gives out only to non-employees. You might think the award has a confusing name, and you would be correct. What you cannot be correct in asserting is that an award makes someone an employee because that award has a confusing name. That isn't a question of "semantics", if you assert that award makes him an employee, you are simply wrong.

I'll repeat what I said in a related thread: I'm not saying it makes him an employee. I'm saying those are bad attempts to argue the title isn't confusing.

And I'll repeat myself: those weren't attempts to argue the title isnt confusing.

Re: Have I Been Pwned 2.0

#316
post #315

Earlier quoted context omitted.

I'll repeat what I said in a related thread: I'm not saying it makes him an employee. I'm saying those are bad attempts to argue the title isn't confusing.

And I'll repeat myself: those weren't attempts to argue the title isnt confusing.

I'm not sure what you're rebutting. This is roughly the thread as I understand it:

1. "Extending your logic, I have a CCIE, so if I ever state I'm a CCIE, I'm an employee of Cisco? [other examples follow]"

2. "All your examples are not things that commonly are job titles, so you are not 'extending logic'."

3. "They are the same class"

4. "No they aren't, those are not job titles, thus they don't imply employment"

...

#. "those weren't attempts to argue the title isnt confusing."

I don't know what you're reading but #1 is doing just that; roughly translated: "Why would 'Microsoft Regional Director' imply he works for Microsoft? If I have a CCIE does that mean I'm an employee of Cisco?"

Re: Have I Been Pwned 2.0

#317
post #314

Earlier quoted context omitted.

I'm not saying it makes him an employee. I'm saying those are bad attempts to argue that it's not a confusing title.

> I'm saying those are bad attempts to argue that it's not a confusing title. You might want to reread, nobody was arguing that. > We can debate semantics but if you describe yourself with a job title attached to a company then I suggest that you have an association which looks rather like ... employment. "Debating semantics" is arguing about which definition to use. There is no valid definition under which you can s…

I'm going to sum this up as

> Its not semantics at all, you just are excusing your own misunderstanding. He didn't describe himself with a job title, and he even explicitly states directly after listing those awards, that he is not an employee of Microsoft.

Yes, I agree. (I believe you think I am arguing against this; for clarity, I am not).

> Extending your logic, I have a CCIE, so if I ever state I'm a CCIE, I'm an employee of Cisco? I have a masters degree by coursework from a university, so I I ever state I have an Msc, I'm an employee of the university? I have an electrical licences issued by EnergySafe Victoria, so if I say I'm an A-Grade Electrician, I'm an employee of EnergySafe Victoria?

I think these are poor examples and reinforce that the confusion was reasonable. That is the only point I've been arguing in this thread.

Re: Have I Been Pwned 2.0

#318
post #22

He should partner with a law firm, for class action lawsuits, for every breach due to negligence (which is probably all of them). Tie in to a banking service, so you can do direct deposits to many millions of people, every time there's new settlements paid, and you'll be a folk hero. Get lawyers who want negligent companies to actually regret the breaches, with judgements that hurt. (Rather than a small settlement th…

[deleted]

Re: Have I Been Pwned 2.0

#319
post #130

Earlier quoted context omitted.

I regularly have doppelgangers that sign up for services with my email address. I've been added to door/visitor notifications. I have received medical information for them. Retirement package info. A telecom internal tracker. A Doubleclick account for a while. Lessons for their children. Countless rewards accounts.

This has literally never happened to me... is your email address "go@away.com" or something?

First initial last name at gMail is one.

Re: Have I Been Pwned 2.0

#320

Earlier quoted context omitted.

We could instead randomly select representatives instead of using popularity contests where the candidates need money for advertisements in order to get popular, or to just even let people know that they exist.[1] https://en.wikipedia.org/wiki/Sortition [1] But the real solution is getting rid of money.

Sure, that's still designing am electoral process. I didn't prescribe any one model in my precious comment.

Ok!
Post reply on HN