Live data from Hacker News

Have I Been Pwned 2.0

troyhunt.com

321–323 of 323 posts

Re: Have I Been Pwned 2.0

#321

Earlier quoted context omitted.

No. It may not be conscious Machiavellian scheme, but it's a common attitude among middle managers. They are extremely sensitive to their reputation, which is why they punish people who make them look bad, even if it's something good for the company. Finding security vulnerabilities or wasted resources is met with an ambiguous hostility. And unfortunately, a lot of people aren't emotionally intelligent enough to reco…

Everyone is extremely sensitive to their reputation. That is just human nature. Someone who can't factor that into their actions and communications is frankly lacking basic social skills.

> Everyone is extremely sensitive to their reputation. That is just human nature

I don't really agree with that, but let's say I do. Middle management is a unique position where their sensitivity is a bigger liability to everyone else. They have some power, but not a lot. They ironically have higher visibility in the company than upper management. And the job requires 0 technical understanding of what they manage.

So that puts them in an awkward position that is often abused. If they feel someone is going to get in trouble, they will make sure that's not them, which is a terribly common instinct. When a developer tells the company there is a problem to address that could threaten the product, that's a good thing that should be welcomed. Instead, many middle managers see that developer as the problem.

> Someone who can't factor that into their actions and communications is frankly lacking basic social skills.

No argument there.

Re: Have I Been Pwned 2.0

#322
post #315

Earlier quoted context omitted.

And I'll repeat myself: those weren't attempts to argue the title isnt confusing.

I'm not sure what you're rebutting. This is roughly the thread as I understand it: 1. "Extending your logic, I have a CCIE, so if I ever state I'm a CCIE, I'm an employee of Cisco? [other examples follow]" 2. "All your examples are not things that commonly are job titles, so you are not 'extending logic'." 3. "They are the same class" 4. "No they aren't, those are not job titles, thus they don't imply employment" ...…

The thread is this.

#1 Troy works for Microsoft.

#2 No Troy doeys, as he clearly states.

#3 Being a Microsoft Regional Director makes him an employee and any claims otherwise are based on some arbitrary semantic distiction, not a real difference

#4 No, there is a real difference. That award is like these other awards and none of them take you anywhere near being an employee.

#5 the arguemnt in #3 is flawed because MRD is confusing and the example title others aren't. (Which misses the point, that using non-confusing examples is much better than using other confusing examples if you want to explain something.)

#6 that doesn't affect the argument being made in #4

#6 repeat ad nauseum

Troy is not a Microsoft employee, no ammount of semantic wiggling will make him a Microsoft employee, no matter how confused people are by the title of the MRD award. That confusion may be justifiable, but doubling down when your error has been explained is not.

Re: Have I Been Pwned 2.0

#323

Earlier quoted context omitted.

You can pay for just one month at a time. I pay now and then and check in on my personal domain – like you, I use dozens of email addresses with a catchall.

The first tier ($4/month) only works for up to 25 aliases. Depending on how many of your aliases have leaked, you may have to pay a lot to perform that check. I wish HIBP had a solution for those of us who are individuals but use domain catchall forwarding as our method for separating accounts. It feels good to see adobe@mydomain.com, newrelic@mydomain.com, internetarchive@mydomain.com, etc. there but not any of the…

Agree completely. I got ownership of my domain before he started charging, but looking now there's only a summary and it lists 45 email addresses in breaches, which means I need to pay a substantial amount to get a report, and I'm the only user of the domain for email.

I wish there was a "I'm just one person, or a small family" tier for this.

Post reply on HN