Live data from Hacker News

Two billion email addresses were exposed

troyhunt.com

381–390 of 470 posts

Re: Two billion email addresses were exposed

#381
post #31

There have been enough data breaches at this point that I'm sure all my info has been exposed multiple times (addresses, SSN, telephone number, email, etc). My email is in over a dozen breaches listed on the been pwned site. I've gotten legal letters about breaches from colleges I applied to, job boards I used, and other places that definitely have a good amount of my past personal information. And that's not even co…

I used per-account email with alias services and password managers. Also started migrating old accounts in free time. Now its pretty easy to tell the source of leak by email addresses as well as sources of spam. --- Per-account alias might sound much, but using sieve filtering [1] is amazing, and you can get a comprehensive filtering solution going with 'envelope to' (the actual address receiving the email) + 'header…

I do this also. I started doing it with physical mail before email existed to sort out the junk mail, so first and last name always contained a reference to the company you were dealing with. Paul Allen back in the 80s said in a Seattle Times interview that it was how he handled it.

Re: Two billion email addresses were exposed

#382
post #376

Earlier quoted context omitted.

You don't need a paid subscription. The API is free. https://haveibeenpwned.com/API/v3

The API is not free. https://haveibeenpwned.com/API/v3#Authorisation

Only if you want to search by account. If you want to search by password, it's free. You can query all your passwords to see which ones are breached, and change those.

> Authorisation is required for all APIs that enable searching HIBP by email address or domain, namely retrieving all breaches for an account, retrieving all pastes for an account, retrieving all breached email addresses for a domain and retrieving all stealer log domains for a breached email addresses. There is no authorisation required for the free Pwned Passwords API.

And searching by account wouldn't tell you anything useful. It would just say "Synthient Credential Stuffing Threat Data". It wouldn't tell you what password to change, because HIBP doesn't know what site the password(s) that it found in "Synthient Credential Stuffing Threat Data" were associated with, and HIBP doesn't maintain a database linking passwords to emails.

Re: Two billion email addresses were exposed

#383
post #18

I think we should stop seeing email address as a secret or something that can be "stolen". Password? who is still storing passwords on their servers, instead of a hash?

It's not about the email addresses themselves. Those are just the identifier by which things can be discovered on haveibeenpwnd. The point is that when email addresses rae stolen/leaked, they're usually accompanied by passwords, addresses, CC information etc.

In some cases the email address combined with the name of that site that leaked it can be enough to get people in trouble. E.g. "niche" dating sites.

Re: Two billion email addresses were exposed

#384
post #31

There have been enough data breaches at this point that I'm sure all my info has been exposed multiple times (addresses, SSN, telephone number, email, etc). My email is in over a dozen breaches listed on the been pwned site. I've gotten legal letters about breaches from colleges I applied to, job boards I used, and other places that definitely have a good amount of my past personal information. And that's not even co…

Same, and I find it really difficult to care about it anymore.

It was leaked through no fault of my own. There are 0 actual consequences to companies doing it. So what am I going to do - stew about it??

Re: Two billion email addresses were exposed

#385

Why are we still using passwords? Why can’t all login be done with asymmetric keys: your public keys are stored on the server, your private keys on the device. Carry a backup pair on your USB and treat it as a key to your house. Any of them got lost? Just delete the respective public key from the service.

[deleted]

Re: Two billion email addresses were exposed

#386
post #45
post #31

There have been enough data breaches at this point that I'm sure all my info has been exposed multiple times (addresses, SSN, telephone number, email, etc). My email is in over a dozen breaches listed on the been pwned site. I've gotten legal letters about breaches from colleges I applied to, job boards I used, and other places that definitely have a good amount of my past personal information. And that's not even co…

I was in the military. China stole my freaking DNA profile . I've given up on worrying about this stuff.

That is awful, but it doesn't lessen the impact of someone who right now has access to your email and or other accounts. China having your DNA profile is not near as impactful as someone actively stealing your identity and potentially ruining your finances. Use 2fa everywhere, and if your email is in this list, you should change your password.

Re: Two billion email addresses were exposed

#387
post #76

Earlier quoted context omitted.

We also wouldn't be having an issue with password leaks as I expect it would be simpler to move on to passkeys (or something else) than implementing a standard way of password rotation...

Except passkeys are an opaque, awful solution. They're hard to explain to users, the implementations want to lock people to specific devices and phones, you can't tell someone a passkey nor type it in easily over a serial link or between two devices which don't have electronic connectivity.

With the right apps, passkeys can be synced across devices (e.g. iCloud Keychain or 1Password).

Re: Two billion email addresses were exposed

#388

This website is very useful, you can target any individuals and find all their secrets (websites they browse, their data and passwords) More seriously, they should notify the owner of the email address privately rather than displaying it publicly, this can be easily weaponized But who cares right, they are monetizing the service..

None of that is true, but you keep your outrage going.

Re: Two billion email addresses were exposed

#389

Earlier quoted context omitted.

I just use + @gmail.com At the end of day day it’s all delivered to myname@gmail.com mailbox, but I can use filters based on part after “+”.

I'd be really surprised if Gmail's + behaviour isn't so well known by spammers that they just strip them off?

Not sure about normalizing recipients' emails but some are definitely aware of it because I've seen spam that asked to "reply back to defi.n.it.ely.not.shady+email@gmail.com" or something.

Re: Two billion email addresses were exposed

#390
Is Troy rotating out old breaches? Because I have 2 email addresses that were definitely part of leaks (I got notified by the parties that were hacked), and one of them used to show up as compromised on the site, but no longer. The other one was part of the Qantas frequent flyer leak (I got an email from Qantas about it), but this address doesn't show up as part of that leak.
Post reply on HN