Live data from Hacker News

Two billion email addresses were exposed

troyhunt.com

281–290 of 470 posts

Re: Two billion email addresses were exposed

#281
post #279

I’m unclear how the new data helps anyone? If you identify you’ve been in a data breach with Adobe for instance, you change your Adobe password. But if you’re in this new dataset there’s no service being pointed at - just “you’ve been breached” which doesn’t really help anyone apart from those who have the same pwd for everything. Maybe they’re the audience, I’m unclear.

I agree. I wish it would tell me the password, there is a good chance I could identify the service that it came from based on the password. This way it doesn’t feel that useful.

Re: Two billion email addresses were exposed

#282
I feel like my phone number and email have already been leaked a long time ago. These days I get spam emails almost every day, and random calls from different cities keep coming in. What I keep wondering is how all this data gets out there. Is there an entire underground business built around selling our information?

Re: Two billion email addresses were exposed

#283

Earlier quoted context omitted.

I used per-account email with alias services and password managers. Also started migrating old accounts in free time. Now its pretty easy to tell the source of leak by email addresses as well as sources of spam. --- Per-account alias might sound much, but using sieve filtering [1] is amazing, and you can get a comprehensive filtering solution going with 'envelope to' (the actual address receiving the email) + 'header…

I just use + @gmail.com At the end of day day it’s all delivered to myname@gmail.com mailbox, but I can use filters based on part after “+”.

I'd be really surprised if Gmail's + behaviour isn't so well known by spammers that they just strip them off?

Re: Two billion email addresses were exposed

#284

Earlier quoted context omitted.

and root disk encryption, unless you have some alternative method set up.

That's the default in this day and age, no?

I mean, probably should be. But for me, no. Well, not my personal computer anyway. That's a mistake, I know. But corporate computer yes.

So no, I don't think "in this day and age" necessarily. And I believe that the vast majority of "normal" users don't do full drive encryption either. But yes, we should.

Re: Two billion email addresses were exposed

#285

Earlier quoted context omitted.

Yes! Me too. Not adding anything here except a confirmation on the above approach. You kind of need your email password as a "break glass" scenario. But mostly, you just need your password manager.

and root disk encryption, unless you have some alternative method set up.

I deliberately dodged there, as you noted. I do not have full disk encryption setup. I know that I'm probably have a very bad day if I come to lose my laptop, etc. I should do this, no doubt.

But I'm not sure. While maybe good password management is starting to soak into common computer usage, I don't think disk encryption is all that common just yet across the average user. It should be. But the average user is just moving to their phone anyway, with face id and encryption by default, instead of maintain their own personal device.

Corporate devices seem to be a bit better in this regard, though.

Re: Two billion email addresses were exposed

#286
post #143

Earlier quoted context omitted.

If you're using the same domain for each of your email address, HIBP has a domain-wide search feature which is free (but you need to register to validate your domain)

I've registered (years and years ago) and I get emails saying how many, but to see which emails they want lots of money. (If I'm wrong their interface is very confusing and I cannot find the free access.) Specifically it says this: > Insufficient subscription. Only subscription-free breaches will be returned for this domain. So I'm able to see 37 email addresses on my domain have been breaches, but I can't see which…

Quoting Troy from a thread beneath the article:

> The easiest approach in that case is to take out the subscription, then immediately cancel it. It'll still last the full month, more here: https://support.haveibeenpwned.com/hc/en-au/articles/7707041...

Re: Two billion email addresses were exposed

#287

Earlier quoted context omitted.

I just use + @gmail.com At the end of day day it’s all delivered to myname@gmail.com mailbox, but I can use filters based on part after “+”.

I'd be really surprised if Gmail's + behaviour isn't so well known by spammers that they just strip them off?

Conversely, I'd assume this pattern is used rarely enough for spammers to even bother fighting it.

Re: Two billion email addresses were exposed

#288

Earlier quoted context omitted.

I just use + @gmail.com At the end of day day it’s all delivered to myname@gmail.com mailbox, but I can use filters based on part after “+”.

Anyone who’s looked at breach data knows to try yourname+service for any service. This does help in filtering spam though

It doesn't have to be literally the service name. Can be any unique alphanumeric suffix you make up randomly. As long as you use a password manager you don't have to remember it.

Re: Two billion email addresses were exposed

#289

Earlier quoted context omitted.

> there does not seem to be any way for _me_, the person affected, to know what password were breached You should be using a unique randomly-generated password for each website. That way, one breach doesn't lead to multiple accounts getting hijacked AND you'll know which passwords were breached solely based on the website list. The only passwords I still keep in my head are: 1. The password to my password manager 2.…

Also if possible, use a unique email address for each site. I know that's not feasible for most people, and some sites (e.g. LinkedIn) are structured so that email addresses become linked, but it does provide useful isolation.

[deleted]

Re: Two billion email addresses were exposed

#290
post #193
post #98

Earlier quoted context omitted.

I self-host through Vaultwarden but I think I miss this. Besides, I feel like paying these guys anyway just for the great product. We use 1Password at $dayjob and it's so primitive by comparison.

TOTP works with vaultwarden.

Yes definitely. Works great.
Post reply on HN