Live data from Hacker News

Two billion email addresses were exposed

troyhunt.com

341–350 of 470 posts

Re: Two billion email addresses were exposed

#341
post #167

Earlier quoted context omitted.

Bitwarden supports TOTP too, even though it's not entirely obvious from the UI.

TOTP inside a password manager doesn't make much sense to me. What's the point of two factor auth if both factors are stored together?

2FA most commonly thwarts server-side compromised passwords. An API can leak credentials and an attacker still can’t access the account without the 2FA app, regardless of which app that is. The threat vector it does open you up to are a) a compromised device or b) someone with access to your master password, secret key and email account. Those are both much harder to do and you’re probably screwed in either case unless you use a ubikey or similar device.

Re: Two billion email addresses were exposed

#342
post #31

There have been enough data breaches at this point that I'm sure all my info has been exposed multiple times (addresses, SSN, telephone number, email, etc). My email is in over a dozen breaches listed on the been pwned site. I've gotten legal letters about breaches from colleges I applied to, job boards I used, and other places that definitely have a good amount of my past personal information. And that's not even co…

[dead]

Re: Two billion email addresses were exposed

#343

Earlier quoted context omitted.

(the keyboard smash username is apropos) > Per-account alias might sound much Not only does this not sound too much, this is a feature Apple offers called Hide My Email: https://support.apple.com/en-us/102548

As someone who uses both, I much rather prefer aliases to hide-my-email for the more important stuff. For one, I can choose the email address "username", which I cannot with Apple's solution. Plus, what happens when I move on from Apple to something else?

But aliases can be easily mapped back to your normal email address, unlike Apple's which are opaque. I, too, am afraid of vendor lock-in though. Sadly, couldn't find a good alternative yet

Re: Two billion email addresses were exposed

#344
post #31

There have been enough data breaches at this point that I'm sure all my info has been exposed multiple times (addresses, SSN, telephone number, email, etc). My email is in over a dozen breaches listed on the been pwned site. I've gotten legal letters about breaches from colleges I applied to, job boards I used, and other places that definitely have a good amount of my past personal information. And that's not even co…

I used per-account email with alias services and password managers. Also started migrating old accounts in free time. Now its pretty easy to tell the source of leak by email addresses as well as sources of spam. --- Per-account alias might sound much, but using sieve filtering [1] is amazing, and you can get a comprehensive filtering solution going with 'envelope to' (the actual address receiving the email) + 'header…

> I used per-account email with alias services and password managers.

For people who want to do this, be sure to get it right. I run a SaaS with a free tier, and I see people register with "fancy+nospam+servicename@gmail.com" addresses. Many of those become undeliverable or are left unread forever because of filtering rules. So when my system sends a warning E-mail that the account will be deleted due to inactivity, it doesn't get read, which leads to suboptimal outcomes for everyone involved.

Re: Two billion email addresses were exposed

#345
post #314

Earlier quoted context omitted.

I just use + @gmail.com At the end of day day it’s all delivered to myname@gmail.com mailbox, but I can use filters based on part after “+”.

With Gmail, also note that firstname.lastname@gmail.com is equivalent to firstnamelastname@gmail.com or fi.rs.tn.am.el.as.tn.am.e@gmail.com As some other comment suggested, these rules are easy to tackle by motivated spammers.

If they were motivated, they wouldn't work as spammers.

Re: Two billion email addresses were exposed

#346
post #53
post #50

I respect Troy Hunt's work. I searched for my email address on https://haveibeenpwned.com/ , and my email was in the latest breach data set. But the site does not give me any way to take action. haveibeenpwned knows what passwords were breached, the people who breached the data knows what passwords were breached, but there does not seem to be any way for _me_, the person affected, to know what password were breached.…

https://haveibeenpwned.com/Passwords

This doesn't help. If the email address check says the address has been exposed it doesn't tell you which password that was used together with that has been exposed. Was it one from 10 years ago you don't even remember? Or that's still actively in use? Which one of my hundreds of passwords?

Re: Two billion email addresses were exposed

#347
post #50

I respect Troy Hunt's work. I searched for my email address on https://haveibeenpwned.com/ , and my email was in the latest breach data set. But the site does not give me any way to take action. haveibeenpwned knows what passwords were breached, the people who breached the data knows what passwords were breached, but there does not seem to be any way for _me_, the person affected, to know what password were breached.…

> But the site does not give me any way to take action. It gives you as much information as you should be given. Any more information would just be spreading around the hacked dataset. It does give you an awful lot of information about the specific hacks that exposed your information, and what was the content of that exposure. You may have been owned, but the way you were owned doesn't really matter e.g. I don't care…

> It does give you an awful lot of information about the specific hacks

No it doesn't. Enter → 5 data breaches → first one says:

> During 2025, the threat-intelligence firm Synthient aggregated 2 billion unique email addresses disclosed in credential-stuffing lists found across multiple malicious internet sources

It doesn't tell me which site or which of the many passwords used together with that address. Just that it has been in a generic data dump.

Re: Two billion email addresses were exposed

#348

Earlier quoted context omitted.

It is officially recommended by the Troy Hunt: https://github.com/HaveIBeenPwned/PwnedPasswordsDownloader/i...

That speaks to a certain confidence in one's servers ability to hold up under load, doesn't it? "Oh you want your own copy? Sure, just thrash seven shades of shit out of the database. Here's how."

Confidence in Cloudflare, for sure.

Re: Two billion email addresses were exposed

#349
post #113

Interestingly, the HIBP data seems to have an expiration date. My email address from the Dropbox data breach [0] is now shown as having no recorded breaches, although it did back in 2016 after HIBP acquired that dataset. [0] https://haveibeenpwned.com/breach/Dropbox

Are you sure you typed the right email address? My 2012 Dropbox leak still shows up for my account.

Yes, I’m sure. The old password from that breach also doesn’t show any hits.

Re: Two billion email addresses were exposed

#350
post #276

Earlier quoted context omitted.

Can anyone with experience with 1Password and Bitwarden share their opinions on each. I've been on 1Password for years and am wondering if I'm missing anything.

1P is closed source and have had a number of breaches in the past. Bitwarden have had none that I'm aware of, and they're FOSS. I however have been preferring ProtonPass lately (also FOSS) and really like the layout over BW.

This is either ignorance or throwing shade at 1Password. Outside of their Okta thing (which didn't impact vaults as far as I'm aware, and was more Okta's fault) they never had a compromise. They are definitely an excellent provider.
Post reply on HN