Live data from Hacker News

Two billion email addresses were exposed

troyhunt.com

421–430 of 470 posts

Re: Two billion email addresses were exposed

#421
post #402
post #377

Earlier quoted context omitted.

Careful with this method. I was unable to purchase plane tickets from Southwest or even change my email address because they changed their parsing rules on me and silently dropped the plus. I found out most airlines don't have a ticket counter to buy a ticket the old fashioned way! But the premier help can issue tickets. Took me two months to have CS get someone to run a DML to remove my "bad" email address.

It's probably easier to tell them "I lost access to that email, I need to set up a new account". People do this all the time. On some level, my employer uses emails as the primary key for customer accounts, the baseline identifier which all information is filed under. It's quite ridiculous.

I did, but the CS agent kept trying to change the email to a new one when I told them I had lost access, and the validation failed because it wanted to send an email to the old address about the email being updated and couldn't. They didn't have the right tools to fix it.

Had to get an engineer involved.

Re: Two billion email addresses were exposed

#422

Earlier quoted context omitted.

I used per-account email with alias services and password managers. Also started migrating old accounts in free time. Now its pretty easy to tell the source of leak by email addresses as well as sources of spam. --- Per-account alias might sound much, but using sieve filtering [1] is amazing, and you can get a comprehensive filtering solution going with 'envelope to' (the actual address receiving the email) + 'header…

I just use + @gmail.com At the end of day day it’s all delivered to myname@gmail.com mailbox, but I can use filters based on part after “+”.

I tried to start doing this. The first site I tried to sign up to said it was an invalid email address.

I would say they could fuck all the way off, but there are legitimate reasons to not let people sign up with an alias (like one person signing up for multiple free trials)

Re: Two billion email addresses were exposed

#424

Earlier quoted context omitted.

I just use + @gmail.com At the end of day day it’s all delivered to myname@gmail.com mailbox, but I can use filters based on part after “+”.

Anyone who’s looked at breach data knows to try yourname+service for any service. This does help in filtering spam though

> Anyone who’s looked at breach data knows to try yourname+service for any service

Since we're all using a unique password for every service - we are doing that, aren't we (!!) - then how does that help?

Re: Two billion email addresses were exposed

#425
As used here, the term "preventative" means an approach or strategy that seeks to prevent email addresses from becoming public and term "remedial" means an approach or strategy that seeks to limit damage if email addresses become public

To reduce risk from data breaches one option is to send less personal data to websites rather than more (preventative)

One old strategy is to not "sign up" for websites unless absolutely necessary (preventative), e.g., to complete a commercial transaction. On the early www, sites publishing public information generally did not ask for email addresses

Another old strategy is to use account-specific addresses and account-specific passwords that identify the account, the date and the computer used, i.e., some user-contructed identifier only known to the computer user (remedial)

Alas today's website operators, including ones offering nothing more than public information, attempt to convince visitors to "sign up" and submit email addresses, even when it is not necessary to access the public information

The website operators benefit from this data collection

As such, data collectors may not recommend that users stop signing up for websites and sending email addresses (preventative). It would reduce their benefit. Instead, they encourage it

HIBP is one such data collector. It requests email addresses in order to search public information

HIBP focuses on behavioural trends with respect to passwords (remedial) instead of behavioural trends in sharing personal data with website operators (preventative)

The operator even admits having an interest in password managers

"My interest in 1Password aside"

Data breaches share private information with the public, making it, detrimentally,^1 public information. This is how it becomes accessible to HIBP

An obvious mitigation strategy is to limit the amount of private information collected (preventative), thereby limiting the amount that could ever be shared with the public in a data breach. This is "preventative"

HIBP is "remedial", i.e., it assumes private information has become public. Without data breaches to collect and search, HIBP would not exist

The two approaches, preventative and remedial, are not mutually exclusive

Both can be used at the same time (preventative plus remedial)

HIBP appears to ignore the preventative approach of modifying behaviour to not submit email addresses to websites. Perhaps because HIBP itself engages in data collection. It solicits email addresses

Unfortunately, one cannot use an account-specific address with HIBP. It solicits addresses that have potentially been used for other accounts

1. Arguably breaches are not detrimental for HIBP since it profits from their existence. If there were a reduction in data breaches, could HIBP continue to successfully solicit more email addresses. If there were behavioural changes the resulted in www users creating fewer accounts and sharing fewer email addresses, would demand for password managers suuch as 1Password be reduced

Re: Two billion email addresses were exposed

#426
post #401
post #344

Earlier quoted context omitted.

> I used per-account email with alias services and password managers. For people who want to do this, be sure to get it right. I run a SaaS with a free tier, and I see people register with "fancy+nospam+servicename@gmail.com" addresses. Many of those become undeliverable or are left unread forever because of filtering rules. So when my system sends a warning E-mail that the account will be deleted due to inactivity,…

It was infuriating to me when normal_email+site_name@gmail.com stopped working for registration on some sites. Fucked up my Costco registration, a variety of other things. This sort of quasi-pseudonymity is required for basic security/privacy in 2025; It's the only way to get a handle on who's allowed to send you email, since we've never bothered to fix spoofing or impose a cost on spam. I've been trying to use it si…

Many spammers will strip the +xxxx out of the emails anyway to not reveal the source of their data so it doesn't matter too much really.

Re: Two billion email addresses were exposed

#427

This website is very useful, you can target any individuals and find all their secrets (websites they browse, their data and passwords) More seriously, they should notify the owner of the email address privately rather than displaying it publicly, this can be easily weaponized But who cares right, they are monetizing the service..

None of that is true, but you keep your outrage going.

If that makes you sleep better at night, you are free to believe none of that is true and just move on..

Re: Two billion email addresses were exposed

#428

Earlier quoted context omitted.

Conversely, I'd assume this pattern is used rarely enough for spammers to even bother fighting it.

But I've seen service providers who insisted on creating some account with a valid email who wouldn't accept a `+` it in their forms...

My favorite was that I could sign-up with the + address but couldn't sign-in. And the support desk rejected that + address too.

The phone support person was confused about that symbol too, what an odd email.

Re: Two billion email addresses were exposed

#429

Earlier quoted context omitted.

This doesn't help. If the email address check says the address has been exposed it doesn't tell you which password that was used together with that has been exposed. Was it one from 10 years ago you don't even remember? Or that's still actively in use? Which one of my hundreds of passwords?

You can use the API to check all of your passwords. Then you'll know the security state of all of your passwords. https://haveibeenpwned.com/API/v3

Doesn't help. Some accounts are old and may not be in my current PW DB. Or they were memorized, or forgotten.

If the thing suggests the EMAIL (+ associated password) has been compromised for some unknown account then to do a risk assessment I would have find which account it belongs to, not which currently-in-use passwords match the same datasets.

Those are different queries, providing different bits of information.

Re: Two billion email addresses were exposed

#430

Earlier quoted context omitted.

> But the site does not give me any way to take action. It gives you as much information as you should be given. Any more information would just be spreading around the hacked dataset. It does give you an awful lot of information about the specific hacks that exposed your information, and what was the content of that exposure. You may have been owned, but the way you were owned doesn't really matter e.g. I don't care…

So it gives me the information that my email has been exposed. Where? In what service? Did my password got leaked too? I can't change password / delete the account if I don't know where. Did any other data got leaked? Anything sensitive? Do I have to cancel my credit card? Were any files leaked as well? My home location? At this point HIBP is next to useless. And how showing me WHAT is in the database about the email…

This information is given for each of the leaked incidents. Troy also explains this in his blog post.
Post reply on HN