Live data from Hacker News

Two billion email addresses were exposed

troyhunt.com

11–20 of 470 posts

Re: Two billion email addresses were exposed

#12
post #4
post #2

Amidst all of these pwnings, we still don't have a standard way to update our passwords from our password managers automatically.

If there was a standard, do you know how long it would take to get adopted across the interwebs.

10 years.

Re: Two billion email addresses were exposed

#13

The downside to having many vanity urls and giving out a unique email address to each website you visit is that you cannot use haveibeenpwned without paying (despite being a single human). I have no idea how many email addresses I've given out over the years, probably hundreds across at least 6 or 7 domains, and they want to charge me a monthly fee to see which of those have been pwned. I understand they gotta make a…

Isn’t the idea that you don’t need haveibeenpowned since you’ll see mails coming in and then know your details have leaked?

For ID fraud, more than an email address has to be leaked.

Re: Two billion email addresses were exposed

#14

The downside to having many vanity urls and giving out a unique email address to each website you visit is that you cannot use haveibeenpwned without paying (despite being a single human). I have no idea how many email addresses I've given out over the years, probably hundreds across at least 6 or 7 domains, and they want to charge me a monthly fee to see which of those have been pwned. I understand they gotta make a…

Just assume they have all been exposed. Email addresses are not secrets under any stretch of the meaning of that word.

It's not the email address itself that I care about, and that's not the service that the site provides. It tells you for which email addresses a related password has been pwned.

Re: Two billion email addresses were exposed

#15

The downside to having many vanity urls and giving out a unique email address to each website you visit is that you cannot use haveibeenpwned without paying (despite being a single human). I have no idea how many email addresses I've given out over the years, probably hundreds across at least 6 or 7 domains, and they want to charge me a monthly fee to see which of those have been pwned. I understand they gotta make a…

Just assume they have all been exposed. Email addresses are not secrets under any stretch of the meaning of that word.

[deleted]

Re: Two billion email addresses were exposed

#16
post #13

The downside to having many vanity urls and giving out a unique email address to each website you visit is that you cannot use haveibeenpwned without paying (despite being a single human). I have no idea how many email addresses I've given out over the years, probably hundreds across at least 6 or 7 domains, and they want to charge me a monthly fee to see which of those have been pwned. I understand they gotta make a…

Isn’t the idea that you don’t need haveibeenpowned since you’ll see mails coming in and then know your details have leaked? For ID fraud, more than an email address has to be leaked.

Have I been pwned will tell me if the associated password for that site leaked. I create unique passwords per site, but lets say my mastercard login gets pwned -- that'd be one I want to change the password for right away.

I might not get an email if someone gets that account info.

Re: Two billion email addresses were exposed

#17
post #11

Can anyone enlighten me why an exposed email address is an issue? I get it if its some kinda admin@foo.com but my private mail, why would I care? Its not like they have my password?

Until they figure out the password to that email and then take over everything else in your life. They are not collecting email address because they are useless.

Re: Two billion email addresses were exposed

#19
I have really started to use the 'Hide my email' feature from iCloud. It's been so nice. If an email gets pwned, which often happens from a service I stopped using many moons ago, then I just deactivate or delete the email address. I imagine many other services provide this feature as well, but it's what's most convenient for me at this time.

Re: Two billion email addresses were exposed

#20
post #11

Can anyone enlighten me why an exposed email address is an issue? I get it if its some kinda admin@foo.com but my private mail, why would I care? Its not like they have my password?

> Oh - and 1.3 billion unique passwords, 625 million of which we'd never seen before either.

It's not just email addresses. It's address + password combos.

But also, how did 2 billion email addresses get exposed? Assuming I give an email address to a company (and only that company) if someone gets access to that email addresss they either got it from me or that company. Knowing the company has sold, lost, or poorly protected my email address tells me they are maybe not worth working with in the future.

Post reply on HN