Live data from Hacker News

Two billion email addresses were exposed

troyhunt.com

351–360 of 470 posts

Re: Two billion email addresses were exposed

#351
post #200

Earlier quoted context omitted.

Now that I'm not only using a Macbook and iPhone, I've been looking for cross-platform solutions. For a week I've been using KeePassXC + Syncthing between four devices. Syncthing is also syncing my Obsidian vaults which has replaced Apple-only Notes.app. Bitwarden is definitely more polished, and Syncthing is definitely (much) more fiddly than using Bitwarden's and Obsidian's ($5/mo) native syncing tools. But I like…

I have used this setup for 6 years or so with KeePassXC and it's fine. Just being mindful of not editing stuff on other devices before the first one has had the chance to sync has been enough to avoid pretty much all sync conflicts. I have only had to resolve those a few times so far, iirc my android client was misconfigured at the time or something. I still recommend Bitwarden for password management for any "laypeo…

Probably due to Obsidian's aggressive autosaving, I did cause a syncthing collision my first day by clicking into a note that I was editing on my other device. Kinda wish desktop Obsidian had a save system more like code editors and less like smartphone apps.

I suppose I can avoid the issue with some discipline.

Re: Two billion email addresses were exposed

#352
post #50

I respect Troy Hunt's work. I searched for my email address on https://haveibeenpwned.com/ , and my email was in the latest breach data set. But the site does not give me any way to take action. haveibeenpwned knows what passwords were breached, the people who breached the data knows what passwords were breached, but there does not seem to be any way for _me_, the person affected, to know what password were breached.…

> But the site does not give me any way to take action. It gives you as much information as you should be given. Any more information would just be spreading around the hacked dataset. It does give you an awful lot of information about the specific hacks that exposed your information, and what was the content of that exposure. You may have been owned, but the way you were owned doesn't really matter e.g. I don't care…

So it gives me the information that my email has been exposed.

Where? In what service? Did my password got leaked too? I can't change password / delete the account if I don't know where.

Did any other data got leaked? Anything sensitive? Do I have to cancel my credit card? Were any files leaked as well? My home location?

At this point HIBP is next to useless.

And how showing me WHAT is in the database about the email I proved I own would be spreading it? At this point if I want to learn it I need to either try to find the torrent with it (spreading it further!) or pay the criminals.

Re: Two billion email addresses were exposed

#353

Earlier quoted context omitted.

TOTP inside a password manager doesn't make much sense to me. What's the point of two factor auth if both factors are stored together?

2FA most commonly thwarts server-side compromised passwords. An API can leak credentials and an attacker still can’t access the account without the 2FA app, regardless of which app that is. The threat vector it does open you up to are a) a compromised device or b) someone with access to your master password, secret key and email account. Those are both much harder to do and you’re probably screwed in either case unle…

How is it possible to have compromised password but not compromised the second factor? I don't understand the theory of leaking not enough factors. What is stopping webmasters from using 100FA?

Re: Two billion email addresses were exposed

#354
post #50

I respect Troy Hunt's work. I searched for my email address on https://haveibeenpwned.com/ , and my email was in the latest breach data set. But the site does not give me any way to take action. haveibeenpwned knows what passwords were breached, the people who breached the data knows what passwords were breached, but there does not seem to be any way for _me_, the person affected, to know what password were breached.…

> there does not seem to be any way for _me_, the person affected, to know what password were breached You should be using a unique randomly-generated password for each website. That way, one breach doesn't lead to multiple accounts getting hijacked AND you'll know which passwords were breached solely based on the website list. The only passwords I still keep in my head are: 1. The password to my password manager 2.…

Nice. Now I'd like to know WHICH password got leaked.

That way the breach impact can quickly be limited.

Troy probably would share that information for a price. Not sure whom to pay though - the "good" guy who won't say a word, or a criminal who will happily share it with me?

It's possible the latter would be cheaper too.

Re: Two billion email addresses were exposed

#355

Earlier quoted context omitted.

Can anyone with experience with 1Password and Bitwarden share their opinions on each. I've been on 1Password for years and am wondering if I'm missing anything.

1password has better UI/UX and is faster but Bitwarden is cheaper, supports prompting of the master password for specific passwords, and better security options (such as app idle settings instead of just device idle) I just trialled it but got a refund

I started paying for 1Password years ago when an annual family plan was $48, and to their credit, they've kept me grandfathered in to that price this whole time.

Re: Two billion email addresses were exposed

#356
post #309
post #50

I respect Troy Hunt's work. I searched for my email address on https://haveibeenpwned.com/ , and my email was in the latest breach data set. But the site does not give me any way to take action. haveibeenpwned knows what passwords were breached, the people who breached the data knows what passwords were breached, but there does not seem to be any way for _me_, the person affected, to know what password were breached.…

The details about the “Stealer Logs” on the dashboard even state: > The websites the stealer logs were captured against are searchable via the HIBP dashboard. There is no way to use the HIBP dashboard to figure out what domains my email address appears against. Am I meant to change all passwords associated with that email address? Or do I need to get a paid subscription to query the API to figure out exactly what pas…

It's quite certainly a up selling attempt. I once spend a couple of hours to see what was actually exposed in the infostealer breach my email appeared (eg: payment data? Physical address? Government id ?) to no avail.

This service is toxic tbh.

Re: Two billion email addresses were exposed

#357

Earlier quoted context omitted.

Now that I'm not only using a Macbook and iPhone, I've been looking for cross-platform solutions. For a week I've been using KeePassXC + Syncthing between four devices. Syncthing is also syncing my Obsidian vaults which has replaced Apple-only Notes.app. Bitwarden is definitely more polished, and Syncthing is definitely (much) more fiddly than using Bitwarden's and Obsidian's ($5/mo) native syncing tools. But I like…

One consideration is that Bitwarden seems to not work fully in an offline state the same way your setup would. I constantly try to edit or add a password while offline and can't. I think this somewhat negates the collision situation though.

That came up during my research and it's one of the reasons I couldn't choose it.

Forcing a read/write right before and after each edit probably simplifies the sync scenario for them but I don't like relying on permanent internet access in my life since it's just not the case.

Re: Two billion email addresses were exposed

#358
post #229

Earlier quoted context omitted.

strongbox is a reasonable app for iOS and you can set it up for sftp to your main self hosted server.

Unfortunately strongbox was sold a few months ago to a somewhat notorious app firm that has the nasty habit of buying popular apps and adding a whole bunch of telemetry. Not something I'd want in a password app. I've switched to KeePassium. Not quite as polished UX, but works for me

I'm using KeePassium and SyncTrain for the syncthing integration on iOS.

SyncTrain has been working well, but all the knobs in the advanced folder settings definitely reminds me that I would never recommend it over Dropbox/iCloud/etc to almost anyone, heh.

But as long as I don't run into frequent problems, I like the idea of p2p device syncing over LAN. The phone in my pocket ends up passing around the latest copy since my other devices are almost never on at the same time. It's kinda cute.

Re: Two billion email addresses were exposed

#360
post #335

Earlier quoted context omitted.

If you read the instructions, you will discover https://haveibeenpwned.com/Passwords which will let you enter a password and securely check if it has been published in a breach. If it has, it is either a simple password that multiple people are using, or a complex secure password that can make you pretty confident it is your password that has been published. 1Password just does the same thing for all of your password…

Letting me check my passwords one at a time is like letting me check my grains of rice individually for poison before eating.

There is also an API
Post reply on HN