Live data from Hacker News

Two billion email addresses were exposed

troyhunt.com

331–340 of 470 posts

Re: Two billion email addresses were exposed

#331

Earlier quoted context omitted.

And one day you've had it with Apple's latest user-hostile shenanigans and switch to Linux. What now? Do you just keep paying for iCloud+ forever?

wouldnt this be the case for any vendor you choose?

yes

Re: Two billion email addresses were exposed

#335
post #50

I respect Troy Hunt's work. I searched for my email address on https://haveibeenpwned.com/ , and my email was in the latest breach data set. But the site does not give me any way to take action. haveibeenpwned knows what passwords were breached, the people who breached the data knows what passwords were breached, but there does not seem to be any way for _me_, the person affected, to know what password were breached.…

If you read the instructions, you will discover https://haveibeenpwned.com/Passwords which will let you enter a password and securely check if it has been published in a breach. If it has, it is either a simple password that multiple people are using, or a complex secure password that can make you pretty confident it is your password that has been published. 1Password just does the same thing for all of your password…

Letting me check my passwords one at a time is like letting me check my grains of rice individually for poison before eating.

Re: Two billion email addresses were exposed

#336
This website is very useful, you can target any individuals and find all their secrets (websites they browse, their data and passwords)

More seriously, they should notify the owner of the email address privately rather than displaying it publicly, this can be easily weaponized

But who cares right, they are monetizing the service..

Re: Two billion email addresses were exposed

#337
Many people here have echoed similar sentiments, but I really wish they would give you any sort of information so you could have any sort of idea of what got pwned and ideally when. Was it a bank account, or some random forum? As it stands the action of even processing this data was of very little utility.

As with roughly a quarter of the planet, I was in this breach. My 1Password Watchtower is green. I cycle important passwords regularly. Back 10-15 years ago my passwords like most peoples were much shorter and not randomly generated. All of them for everything show up in the passwords search.

The utility of Have I Been Pwned approaches zero the longer you have been on the internet, and I have been on the internet since the late 1990s.

We're left in a place where everyone but the victim knows the compromised account, and that's just kind of absurdly useless.

Re: Two billion email addresses were exposed

#338
post #45
post #31

There have been enough data breaches at this point that I'm sure all my info has been exposed multiple times (addresses, SSN, telephone number, email, etc). My email is in over a dozen breaches listed on the been pwned site. I've gotten legal letters about breaches from colleges I applied to, job boards I used, and other places that definitely have a good amount of my past personal information. And that's not even co…

I was in the military. China stole my freaking DNA profile . I've given up on worrying about this stuff.

DNA is actually almost impossible to keep secret if someone really wants it - you basically shed your entire DNA every time you touch anything

Re: Two billion email addresses were exposed

#339
post #337

Many people here have echoed similar sentiments, but I really wish they would give you any sort of information so you could have any sort of idea of what got pwned and ideally when. Was it a bank account, or some random forum? As it stands the action of even processing this data was of very little utility. As with roughly a quarter of the planet, I was in this breach. My 1Password Watchtower is green. I cycle importa…

> The utility of Have I Been Pwned approaches zero the longer you have been on the internet, and I have been on the internet since the late 1990s.

I mean if your 1Password is green then HIBP has definitely helped.

First of all, without HIBP, you wouldn't have Watchtower.

HIBP has raised awareness on having unique passwords per site.

HIBP has achieved that multiple services now can and check if particular password is leaked or not.

Of course you could argue that since your security hygiene is so good you don't need HIBP. True. Let's pretend every people on planet will be generating unique passwords per service. Great. HIBP will have achieved enourmous job of making the planet more secure.

And still a notification if you appear in some breach that can be attributed to a service - good signal to change password.

Hats off for you cycling the password.. Have you ever ran into problems with that? Say you kinda rotated password but it no longer is accepted or something?

Re: Two billion email addresses were exposed

#340
post #335

Earlier quoted context omitted.

If you read the instructions, you will discover https://haveibeenpwned.com/Passwords which will let you enter a password and securely check if it has been published in a breach. If it has, it is either a simple password that multiple people are using, or a complex secure password that can make you pretty confident it is your password that has been published. 1Password just does the same thing for all of your password…

Letting me check my passwords one at a time is like letting me check my grains of rice individually for poison before eating.

Use a tool

https://monitor.mozilla.org/

https://watchtower.1password.com/

https://bitwarden.com/help/reports/#exposed-passwords-report

Post reply on HN