Live data from Hacker News

Two billion email addresses were exposed

troyhunt.com

221–230 of 470 posts

Re: Two billion email addresses were exposed

#221
post #167

Earlier quoted context omitted.

I switched from Bitwarden to Proton pass (because we got Proton family) and I find to be equally good. Ineven find sharing credentials a bit easier as it does not require organizations, you can just share with individuals. Proton also has a separate 2fa totp app.

Bitwarden supports TOTP too, even though it's not entirely obvious from the UI.

TOTP inside a password manager doesn't make much sense to me. What's the point of two factor auth if both factors are stored together?

Re: Two billion email addresses were exposed

#222

If there's no meaningful reward or punishment for keeping or leaking PII, companies won't do anything about it. They'll keep collecting sensitive inf unless they're educated or forced not to collect unnecessary PII.

We need to make storing customer data and recommendation algorithms a liability.

Re: Two billion email addresses were exposed

#223
When you have days like this, 2-10 billion and you want to search it, what are the cheapest options? Reindexing could be slow, be search should be reasonably quick. It would be really expensive to do this all in, say, Elastic, right? Especially if you had a bunch of columns?

Re: Two billion email addresses were exposed

#224
post #204

Earlier quoted context omitted.

The number of years I got "free credit monitoring" I can pass it down to my children . . .

I feel like only in the US is credit monitoring something sold as an optional service. I got a confirmation mail from System76, because apparently they feel the need to validate my credit card can’t be used without my approval, but my back does this by default…

Credit monitoring has nothing to do with Credit Cards.

Most banks in America indeed do offer (for free) the option to be notified for each transactions if you want.

Re: Two billion email addresses were exposed

#225
Anyone have thoughts on Bitwarden / 1Password / Proton Pass?

Proton Pass feels too new for me but eagerly awaiting good feedbacks / reviews. However, "don't put all your eggs in one basket" might apply here.

Went with Bitwarden instead of 1Password since its open source, and I imagine (in my uninformed opinion) that a larger userbase by being free means more issues might be encountered and ironed out.

Re: Two billion email addresses were exposed

#226
post #138

Earlier quoted context omitted.

5894 means that the password appeared 5894 times in the dataset. 5894 is not the password associated with the hash.

Yes, it did mean what I thought, then. But I guess some passwords appear far more often than that in the dataset.

Some passwords are far more commonly used than others; that isn't surprising.

Re: Two billion email addresses were exposed

#227

Earlier quoted context omitted.

> Bitwarden Best when paid for so you can do 2FA with TOTP codes!

The moment you put TOTP in Bitwarden it is no longer a 'second factor'. Pretty bad security advice to be honest. Better to use hardware tokens or a secure phone (with enclave) instead (never SMS though).

In most cases a true second factor isn't really what any involved party cares about.

My bank (I mean, they use SMS, but pretend they use TOTP) just care about not having to spend money on support because I used "password1!" as my password for every account and lose all my money.

I just want to log in to my bank.

If I've got a long, random, unique, securely-stored password, I don't actually care about having a second factor, I'm just enabling TOTP so that I don't have to copy/paste codes from my email or phone.

Re: Two billion email addresses were exposed

#228
post #95

Earlier quoted context omitted.

Gonna be a very weird day for you when China's clone army invades us.

If nothing else, I guess one should at least be kinda proud that of all stolen DNAs, yours is the one they end up making a clone army out of.

5,000,000 Kulahans invading America would not be very effective thus I have defeated China myself, no thanks are necessary.

Re: Two billion email addresses were exposed

#229

Earlier quoted context omitted.

+1 for Bitwarden. It is literally the best solution out there. Been getting to increase uptake in personal circles with (very) limited success. The wife keeps trying to convince me that the ship has sailed in trying to protect info online. She's probably right.

Now that I'm not only using a Macbook and iPhone, I've been looking for cross-platform solutions. For a week I've been using KeePassXC + Syncthing between four devices. Syncthing is also syncing my Obsidian vaults which has replaced Apple-only Notes.app. Bitwarden is definitely more polished, and Syncthing is definitely (much) more fiddly than using Bitwarden's and Obsidian's ($5/mo) native syncing tools. But I like…

strongbox is a reasonable app for iOS and you can set it up for sftp to your main self hosted server.

Re: Two billion email addresses were exposed

#230
post #167

Earlier quoted context omitted.

Bitwarden supports TOTP too, even though it's not entirely obvious from the UI.

TOTP inside a password manager doesn't make much sense to me. What's the point of two factor auth if both factors are stored together?

Bingo. You need to use a different totp.
Post reply on HN