Live data from Hacker News

Two billion email addresses were exposed

troyhunt.com

1–10 of 470 posts

Re: Two billion email addresses were exposed

#5
The downside to having many vanity urls and giving out a unique email address to each website you visit is that you cannot use haveibeenpwned without paying (despite being a single human). I have no idea how many email addresses I've given out over the years, probably hundreds across at least 6 or 7 domains, and they want to charge me a monthly fee to see which of those have been pwned.

I understand they gotta make a buck, but I find it interesting this is the first real negative to running a unique email address per company/site I work with.

Re: Two billion email addresses were exposed

#6
post #2

Amidst all of these pwnings, we still don't have a standard way to update our passwords from our password managers automatically.

if we could have standardization like that, we wouldn't need passwords

We also wouldn't be having an issue with password leaks as I expect it would be simpler to move on to passkeys (or something else) than implementing a standard way of password rotation...

Re: Two billion email addresses were exposed

#8

The downside to having many vanity urls and giving out a unique email address to each website you visit is that you cannot use haveibeenpwned without paying (despite being a single human). I have no idea how many email addresses I've given out over the years, probably hundreds across at least 6 or 7 domains, and they want to charge me a monthly fee to see which of those have been pwned. I understand they gotta make a…

Just assume they have all been exposed.

Email addresses are not secrets under any stretch of the meaning of that word.

Re: Two billion email addresses were exposed

#9
My data was exposed in one of the Facebook leaks and it turned out I had an old email on my Facebook account with a domain I had since let lapse and abandoned. Someone else registered the domain and tried to take over my Facebook account by sending a password reset request using it. Luckily I had 2FA and I guess Facebook's fraud alerts picked it up so It wasn't successful.

I guess what I want to say is beware that even something as innocuous as an email being leaked can cause problems, and make sure you delete any unused addresses from your accounts!

Re: Two billion email addresses were exposed

#10

The downside to having many vanity urls and giving out a unique email address to each website you visit is that you cannot use haveibeenpwned without paying (despite being a single human). I have no idea how many email addresses I've given out over the years, probably hundreds across at least 6 or 7 domains, and they want to charge me a monthly fee to see which of those have been pwned. I understand they gotta make a…

I'm in the same boat. I track all of the unique addresses I use (via my password manager) so I guess I could just check them all against HiBP's database. Kind of a pain in the ass, though.
Post reply on HN