Live data from Hacker News

A decade of Have I Been Pwned

troyhunt.com

1–10 of 181 posts

Re: A decade of Have I Been Pwned

#2
> Not to mention all the other weird variations including haveibeenburned.com, haveigotpwned.com, haveibeenrekt.com and after someone made the suggestion following the revelation that PornHub follows me, haveibeenfucked.com

That is honestly pretty hilarious of a side effect of media fame!

Re: A decade of Have I Been Pwned

#3

> Not to mention all the other weird variations including haveibeenburned.com, haveigotpwned.com, haveibeenrekt.com and after someone made the suggestion following the revelation that PornHub follows me, haveibeenfucked.com That is honestly pretty hilarious of a side effect of media fame!

[dead]

Re: A decade of Have I Been Pwned

#5
post #4

For those privacy focused, here's how you can remove your information from their public search ability. https://haveibeenpwned.com/OptOut

You have to solve a Google ReCaptcha though, which privacy-focused folks won’t like.

Also, just FYI, “The controller of the domain your email address is on will still see you in domain searches.”

Re: A decade of Have I Been Pwned

#6
post #4

For those privacy focused, here's how you can remove your information from their public search ability. https://haveibeenpwned.com/OptOut

Seems slightly useless to opt-out of HIBP when your email is still in Collection #1 or Anti Public Combo List or whatever.

Anyone wanting to do something nefarious with the emails will surely download the full source lists rather than try and scrape the aggregation site.

Re: A decade of Have I Been Pwned

#7
post #5
post #4

For those privacy focused, here's how you can remove your information from their public search ability. https://haveibeenpwned.com/OptOut

You have to solve a Google ReCaptcha though, which privacy-focused folks won’t like. Also, just FYI, “The controller of the domain your email address is on will still see you in domain searches.”

To merely use the service, you have to solve a seemingly infinite cycle of hcaptchas from cloudflare, this recaptcha is much more decent to users from 3rd world countries!

Re: A decade of Have I Been Pwned

#8

> Not to mention all the other weird variations including haveibeenburned.com, haveigotpwned.com, haveibeenrekt.com and after someone made the suggestion following the revelation that PornHub follows me, haveibeenfucked.com That is honestly pretty hilarious of a side effect of media fame!

> haveibeenfucked.com

Years ago we had friends, a couple in which the wife was pregnant. They were actually a bit embarrassed that “everyone will know that we ‘did it’”. A level of squeamishishness I could not have imagined!

Re: A decade of Have I Been Pwned

#9
post #6
post #4

For those privacy focused, here's how you can remove your information from their public search ability. https://haveibeenpwned.com/OptOut

Seems slightly useless to opt-out of HIBP when your email is still in Collection #1 or Anti Public Combo List or whatever. Anyone wanting to do something nefarious with the emails will surely download the full source lists rather than try and scrape the aggregation site.

he's become a very tempting target in himself that gets more tempting with each additional database added

I wonder if he actually deletes the data...

Re: A decade of Have I Been Pwned

#10
It is worth noting the user awareness impact HaveIBeenPwned has had.

On the other hand, I feel like SpyCloud does not get enough credit for having a dataset 30x bigger and working directly with companies to actually mitigate credential reuse. If you've ever been prompted at login to a major website or received an email asking you to reset a password because it was used in multiple places, there is a good chance SpyCloud is behind it.

Post reply on HN