Live data from Hacker News

Two billion email addresses were exposed

troyhunt.com

301–310 of 470 posts

Re: Two billion email addresses were exposed

#301
post #31

There have been enough data breaches at this point that I'm sure all my info has been exposed multiple times (addresses, SSN, telephone number, email, etc). My email is in over a dozen breaches listed on the been pwned site. I've gotten legal letters about breaches from colleges I applied to, job boards I used, and other places that definitely have a good amount of my past personal information. And that's not even co…

I used per-account email with alias services and password managers. Also started migrating old accounts in free time. Now its pretty easy to tell the source of leak by email addresses as well as sources of spam. --- Per-account alias might sound much, but using sieve filtering [1] is amazing, and you can get a comprehensive filtering solution going with 'envelope to' (the actual address receiving the email) + 'header…

I also use per-account emails, but not sieve filtering. Catch-all is helpful for throw-aways, aliases for the more important stuff.

It's super-easy to figure out who leaks my emails to whom, so I can easily disable both the leaker and the people who leaked.

Much more user-friendly than Apple's hide-my-email.

Re: Two billion email addresses were exposed

#302

Earlier quoted context omitted.

I used per-account email with alias services and password managers. Also started migrating old accounts in free time. Now its pretty easy to tell the source of leak by email addresses as well as sources of spam. --- Per-account alias might sound much, but using sieve filtering [1] is amazing, and you can get a comprehensive filtering solution going with 'envelope to' (the actual address receiving the email) + 'header…

(the keyboard smash username is apropos) > Per-account alias might sound much Not only does this not sound too much, this is a feature Apple offers called Hide My Email: https://support.apple.com/en-us/102548

As someone who uses both, I much rather prefer aliases to hide-my-email for the more important stuff. For one, I can choose the email address "username", which I cannot with Apple's solution. Plus, what happens when I move on from Apple to something else?

Re: Two billion email addresses were exposed

#303

Earlier quoted context omitted.

+1 for Bitwarden. It is literally the best solution out there. Been getting to increase uptake in personal circles with (very) limited success. The wife keeps trying to convince me that the ship has sailed in trying to protect info online. She's probably right.

Can anyone with experience with 1Password and Bitwarden share their opinions on each. I've been on 1Password for years and am wondering if I'm missing anything.

1password has better UI/UX and is faster but Bitwarden is cheaper, supports prompting of the master password for specific passwords, and better security options (such as app idle settings instead of just device idle)

I just trialled it but got a refund

Re: Two billion email addresses were exposed

#304

Earlier quoted context omitted.

Can anyone with experience with 1Password and Bitwarden share their opinions on each. I've been on 1Password for years and am wondering if I'm missing anything.

I might be that guy soon. I really don't like Bitwarden's extensions, they have clunky UX, are slow and often don't even respect my settings. Autofill is a crapshoot, especially on Android. And they have performance issues with the Firefox and Chrome(-based) extensions so it's not even platform specific.

Same experience here

Re: Two billion email addresses were exposed

#305
post #19

I have really started to use the 'Hide my email' feature from iCloud. It's been so nice. If an email gets pwned, which often happens from a service I stopped using many moons ago, then I just deactivate or delete the email address. I imagine many other services provide this feature as well, but it's what's most convenient for me at this time.

Can anyone recommend a good third party service that provides similar functionality and a great user experience? For those of us who don't want to entrust this to Apple and who'd like to use our own domain?

addy.io

Re: Two billion email addresses were exposed

#306

Anyone have thoughts on Bitwarden / 1Password / Proton Pass? Proton Pass feels too new for me but eagerly awaiting good feedbacks / reviews. However, "don't put all your eggs in one basket" might apply here. Went with Bitwarden instead of 1Password since its open source, and I imagine (in my uninformed opinion) that a larger userbase by being free means more issues might be encountered and ironed out.

I suggest KeepassXC + SyncThing + KeepassDX (for Android)

Re: Two billion email addresses were exposed

#307

Anyone have thoughts on Bitwarden / 1Password / Proton Pass? Proton Pass feels too new for me but eagerly awaiting good feedbacks / reviews. However, "don't put all your eggs in one basket" might apply here. Went with Bitwarden instead of 1Password since its open source, and I imagine (in my uninformed opinion) that a larger userbase by being free means more issues might be encountered and ironed out.

If you're happy with Bitwarden, I think you should stick to that. I'm currently using 1Password, I switches after the security issues with Lastpass. Later I did try Bitwarden but was unhappy with the ability to correctly identify username and password fields on websites. Others tell me that they have more a better experience with Bitwarden, so I might have to give it a try again.

1Password is really nice, but it's also expensive, compared to Bitwarden.

Re: Two billion email addresses were exposed

#308

Why are we still using passwords? Why can’t all login be done with asymmetric keys: your public keys are stored on the server, your private keys on the device. Carry a backup pair on your USB and treat it as a key to your house. Any of them got lost? Just delete the respective public key from the service.

How are you going to sign in and delete the public key, if you lost the private key?

This is exactly why so many do not want passkey, the recovery options aren't exactly great.

Re: Two billion email addresses were exposed

#309
post #50

I respect Troy Hunt's work. I searched for my email address on https://haveibeenpwned.com/ , and my email was in the latest breach data set. But the site does not give me any way to take action. haveibeenpwned knows what passwords were breached, the people who breached the data knows what passwords were breached, but there does not seem to be any way for _me_, the person affected, to know what password were breached.…

The details about the “Stealer Logs” on the dashboard even state:

> The websites the stealer logs were captured against are searchable via the HIBP dashboard.

There is no way to use the HIBP dashboard to figure out what domains my email address appears against.

Am I meant to change all passwords associated with that email address? Or do I need to get a paid subscription to query the API to figure out exactly what password(s) to change?

This has always confused me. On the one hand, HIBP is an invaluable service, but, on the other, it does nothing more than stating you’re in trouble, with no clear way forward.

Re: Two billion email addresses were exposed

#310
This is exactly while I and incredibly reluctant to sign up for any new service. You have to offer me something very special for me to ever create an account with your site. A free trial simply isn't enough for me to wanting to deal with yet another account, and I have a password manager.

Sign in with Google/Apple/Facebook/Microsoft/Github, whatever, could have been a solution, but I don't believe any of them to trustworthy long term.

Post reply on HN