This is a pretty useful service. I do check sites tracking these compromises on occasion, and I know at least one password I used before has been compromised, but it wasn't one I'd used in years. My biggest concern is that your subject line sounds like plenty of spam/phishing emails, and your URL may get blacklisted by email services if you do this often enough. From a slightly higher effort standpoint, you might be…
The problem isn't that the subject line sounds spammy, it's that the spam mails try to sound legitimate. This may in turn create problems for actually legit messages. Maybe putting the scraped password in the subject line catches the recipients' attention.
“I Emailed 97,931 Users Their Passwords”
11–20 of 72 posts
Re: “I Emailed 97,931 Users Their Passwords”
#12cached version -> http://webcache.googleusercontent.com/search?q=cache:tQP6ur9...
Re: “I Emailed 97,931 Users Their Passwords”
#13Re: “I Emailed 97,931 Users Their Passwords”
#14> Including one request to F k off. If someone had just sent me an email letting me know that my email and password are out there in the wild, "fuck off" would not be my first reaction. That's just rude.
Re: “I Emailed 97,931 Users Their Passwords”
#15> Including one request to F k off. If someone had just sent me an email letting me know that my email and password are out there in the wild, "fuck off" would not be my first reaction. That's just rude.
Re: “I Emailed 97,931 Users Their Passwords”
#16While I support this valiant effort, aren't there often legal implications to doing this?
It might be considered spam for one thing. The emails are unsolicited and it might be seen as a subtle promotion of the urhack project. I'm not sure that collecting and sending the passwords is illegal but I'm sure that wouldn't stop some litigious person from causing grief.
Re: “I Emailed 97,931 Users Their Passwords”
#17Re: “I Emailed 97,931 Users Their Passwords”
#18> Including one request to F k off. If someone had just sent me an email letting me know that my email and password are out there in the wild, "fuck off" would not be my first reaction. That's just rude.
Re: “I Emailed 97,931 Users Their Passwords”
#19> The thank you notes I got were sincere. One of them validated the entire effort when the person indicated that they use the same password for everything and wanted to know which account had been compromised
I hope they don't only change the password on that one site!
Re: “I Emailed 97,931 Users Their Passwords”
#20Did you track open rates? I would be curious to see what those numbers look like.