Live data from Hacker News

Two billion email addresses were exposed

troyhunt.com

101–110 of 470 posts

Re: Two billion email addresses were exposed

#101
post #91

Are there any email services which allow basically unlimited aliases with long, random names? I'm using my own domain right now, but that can only uncover who has leaked my data; does not provide additional privacy.

I know you can set up "catch-all" email with a custom domain through Proton Mail.

I don't think there's any limit on gmail + codes.

Re: Two billion email addresses were exposed

#102
post #91

Are there any email services which allow basically unlimited aliases with long, random names? I'm using my own domain right now, but that can only uncover who has leaked my data; does not provide additional privacy.

duckduckgo's free email aliases. Can use it as a front-end and keep your existing domain

Re: Two billion email addresses were exposed

#103
post #52

Earlier quoted context omitted.

It does. I just checked mine today. I can see exactly which individual email addresses in my domain where exposed and in which data leak. I have never paid for it.

Interesting. I'd love to see where you're seeing that. I'll go poke at the site a little more. Edit: When I try to do a domain search I get told: > Domain search restricted: You don't have an active subscription so you're limited to searching domains with up to 10 breached addresses (excluding addresses in spam lists). My domain has 11 breached addresses.

I log in. Click on Business -> Domains. Then click on the looking glass under "Actions" on my domain. I can there see all my addresses an Pwned Sites.

But I think you are right, because I only have 3 breached addresses under my domain (I do see the 10 addresses wording under subscriptions)

Re: Two billion email addresses were exposed

#104
I checked a few of my passwords and a few random ideas. It turns out that I'm not the only one who finds the Star wars drone names a good inspiration for a password, but the rest were okay. Proud that I found a password which leaked in only one breech. Whoever has used "feromancer" as a pass, congrats, you might be unique among a big part of humanity.

Re: Two billion email addresses were exposed

#105
post #45
post #31

There have been enough data breaches at this point that I'm sure all my info has been exposed multiple times (addresses, SSN, telephone number, email, etc). My email is in over a dozen breaches listed on the been pwned site. I've gotten legal letters about breaches from colleges I applied to, job boards I used, and other places that definitely have a good amount of my past personal information. And that's not even co…

I was in the military. China stole my freaking DNA profile . I've given up on worrying about this stuff.

The number of years I got "free credit monitoring" I can pass it down to my children . . .

Re: Two billion email addresses were exposed

#106
post #91

Are there any email services which allow basically unlimited aliases with long, random names? I'm using my own domain right now, but that can only uncover who has leaked my data; does not provide additional privacy.

check simple login. they were both by Proton, but you can use them without the parent.

Re: Two billion email addresses were exposed

#107
I switched to using masked emails with Fastmail primarily so I could see who sold my data. The potential security benefit was not really a driver. Having 1Password be able to generate a unique email makes it a no-brainer these days. For those services that require a username that is not your email, they can usually be used without the domain part. Works really well.

I even wrote a tiny little local only web app that I can use to generate a masked email on my phone, so when I need an email for an in person thing I can just show them my brand new weird email directly on my phone.

Re: Two billion email addresses were exposed

#108
post #31

There have been enough data breaches at this point that I'm sure all my info has been exposed multiple times (addresses, SSN, telephone number, email, etc). My email is in over a dozen breaches listed on the been pwned site. I've gotten legal letters about breaches from colleges I applied to, job boards I used, and other places that definitely have a good amount of my past personal information. And that's not even co…

+1 for Bitwarden. It is literally the best solution out there. Been getting to increase uptake in personal circles with (very) limited success. The wife keeps trying to convince me that the ship has sailed in trying to protect info online. She's probably right.

I switched from Bitwarden to Proton pass (because we got Proton family) and I find to be equally good. Ineven find sharing credentials a bit easier as it does not require organizations, you can just share with individuals.

Proton also has a separate 2fa totp app.

Re: Two billion email addresses were exposed

#109
post #107

I switched to using masked emails with Fastmail primarily so I could see who sold my data. The potential security benefit was not really a driver. Having 1Password be able to generate a unique email makes it a no-brainer these days. For those services that require a username that is not your email, they can usually be used without the domain part. Works really well. I even wrote a tiny little local only web app that…

Any interesting finds on companies that tried to sell your data?

Re: Two billion email addresses were exposed

#110

Earlier quoted context omitted.

[flagged]

HaveIBeenPwned has been around for ages and it does not send your password to the server - you can check it with the browser console. It hashes it, sends a range of the hash to the server, server replies with a list of hashes that match that range and it's checked locally for a match.

Man, there's a ton of non-obvious ways they could exfiltrate that. I'm not going to read their code.
Post reply on HN