Live data from Hacker News

Two billion email addresses were exposed

troyhunt.com

71–80 of 470 posts

Re: Two billion email addresses were exposed

#71
post #24
post #9

My data was exposed in one of the Facebook leaks and it turned out I had an old email on my Facebook account with a domain I had since let lapse and abandoned. Someone else registered the domain and tried to take over my Facebook account by sending a password reset request using it. Luckily I had 2FA and I guess Facebook's fraud alerts picked it up so It wasn't successful. I guess what I want to say is beware that ev…

What a lot of work to capture one account.

I can think of a lot of ways that would be worth it.

* blackmail the account owner

* make up an illness, create a donation page and get all their friends to donate

* find all connections over a certain age and disguise a phishing vector as literally anything!

* so many more

Re: Two billion email addresses were exposed

#72

Is there any real drawback to just never giving your real name or address to service providers to minimise the chance of identity theft? Most likely it’s against terms of service, but other than account suspension are you likely to suffer any legal consequences?

Service providers generally use your name and address to validate your billing method. If you can pay by some method that doesn’t require name or address then go ahead and use a fake name.

Depending on the service, the billing data may be in its own database outside of the user tables.

Re: Two billion email addresses were exposed

#73
post #70

Earlier quoted context omitted.

[flagged]

> Passwords are protected with an anonymity model, so we never see them (it's processed in the browser itself), but if you're wary, just check old ones you may suspect. That could mean one might be able to disconnect from the internet while checking.

No, it doesn't mean that, that's ridiculous. How would that work? Magic?

Re: Two billion email addresses were exposed

#74

Earlier quoted context omitted.

I use Bitwarden with a Vaultwarden server so I have some familiarity. Bitwarden checks new passwords against HiBP. I'm not aware of functionality where it can retroactively check old email addresses or passwords to see if they're included in a breach.

It's under Reports: https://bitwarden.com/help/reports/

Ahh, okay. I assume that's a part of the Bitwarden offering, presumably happening server-side. I'm just using their official client w/ a Vaultwarden server.

Re: Two billion email addresses were exposed

#75
post #50

I respect Troy Hunt's work. I searched for my email address on https://haveibeenpwned.com/ , and my email was in the latest breach data set. But the site does not give me any way to take action. haveibeenpwned knows what passwords were breached, the people who breached the data knows what passwords were breached, but there does not seem to be any way for _me_, the person affected, to know what password were breached.…

At one point I responded to a haveibeenpwned notice by immediately having the user reset a password.

I've got over 200 users in a domain search (edit: for this particular incident), and nearly all of them were in previous credential breaches that were probably stuffed into this one. I'm not going to put them through a forced annoyance given how likely it is the breached password is not their current one, and I'm urging people to start moving in this direction unless you obtain a more concrete piece of advice.

Re: Two billion email addresses were exposed

#76

Earlier quoted context omitted.

if we could have standardization like that, we wouldn't need passwords

We also wouldn't be having an issue with password leaks as I expect it would be simpler to move on to passkeys (or something else) than implementing a standard way of password rotation...

Except passkeys are an opaque, awful solution.

They're hard to explain to users, the implementations want to lock people to specific devices and phones, you can't tell someone a passkey nor type it in easily over a serial link or between two devices which don't have electronic connectivity.

Re: Two billion email addresses were exposed

#77
post #53

Earlier quoted context omitted.

https://haveibeenpwned.com/Passwords

[flagged]

HaveIBeenPwned has been around for ages and it does not send your password to the server - you can check it with the browser console. It hashes it, sends a range of the hash to the server, server replies with a list of hashes that match that range and it's checked locally for a match.

Re: Two billion email addresses were exposed

#78
post #31

There have been enough data breaches at this point that I'm sure all my info has been exposed multiple times (addresses, SSN, telephone number, email, etc). My email is in over a dozen breaches listed on the been pwned site. I've gotten legal letters about breaches from colleges I applied to, job boards I used, and other places that definitely have a good amount of my past personal information. And that's not even co…

+1 for Bitwarden. It is literally the best solution out there. Been getting to increase uptake in personal circles with (very) limited success. The wife keeps trying to convince me that the ship has sailed in trying to protect info online. She's probably right.

> Bitwarden

Best when paid for so you can do 2FA with TOTP codes!

Re: Two billion email addresses were exposed

#79
post #50

I respect Troy Hunt's work. I searched for my email address on https://haveibeenpwned.com/ , and my email was in the latest breach data set. But the site does not give me any way to take action. haveibeenpwned knows what passwords were breached, the people who breached the data knows what passwords were breached, but there does not seem to be any way for _me_, the person affected, to know what password were breached.…

The problem with breaches like the latest data set is that there's no source on where the breach came from, it's an aggregate from multiple breaches. They can't tell you that info because it's not in the initial data set.

Re: Two billion email addresses were exposed

#80
post #19

I have really started to use the 'Hide my email' feature from iCloud. It's been so nice. If an email gets pwned, which often happens from a service I stopped using many moons ago, then I just deactivate or delete the email address. I imagine many other services provide this feature as well, but it's what's most convenient for me at this time.

Can anyone recommend a good third party service that provides similar functionality and a great user experience?

For those of us who don't want to entrust this to Apple and who'd like to use our own domain?

Post reply on HN