Live data from Hacker News

Pwned or Bot

troyhunt.com

11–20 of 89 posts

Re: Pwned or Bot

#12

I pay for my email that gives me a lot of aliases and most of them have not been pwned yet. So with his tool I would be flagged as a bot. Honestly, doesn't sound like a great idea to be frank. There must be large swaths of people that have either been careful or have specific emails that they use for certain purposes that haven't been pwned. The question, what should happen if I haven't been pwned? Should I not be ab…

Edit: I misunderstood Troy. Original comment: No, it doesn't penalize them (at least not his idea, implementations might), it simply fast tracks pwned emails and doesn't apply the normal bot checks that would otherwise apply to everyone.

That's not how he's suggesting it would work. All checks would normally be applied to build a "how human are you" or "humanness" score. He's suggesting a pwned email test and arguing it would be a good signal for "humanness". The implementation might not make it an explicit penalty (-1 to your "humanness" score), but not being pwned might not help your case (+1 if you are pwned, but +0 if you're not).

Re: Pwned or Bot

#13

I pay for my email that gives me a lot of aliases and most of them have not been pwned yet. So with his tool I would be flagged as a bot. Honestly, doesn't sound like a great idea to be frank. There must be large swaths of people that have either been careful or have specific emails that they use for certain purposes that haven't been pwned. The question, what should happen if I haven't been pwned? Should I not be ab…

It's not his idea, he's saying that there are people out there who are already (mis)using the data for this.

Re: Pwned or Bot

#14
post #3

This is a cute "hack" for bot detection, but it's too unpredictable for the real world. Far too many users with good security hygiene are penalized by this system Plus, this might incentivize hackers to defeat the system by logging into and using email accounts pwned in these breaches.

The only security hygiene that can stop your email from leaking is using a different address for literally every service you ever log into. This is of course possible with your own domain, but in practice totally infeasible for the vast majority of people.

Re: Pwned or Bot

#15
post #3

This is a cute "hack" for bot detection, but it's too unpredictable for the real world. Far too many users with good security hygiene are penalized by this system Plus, this might incentivize hackers to defeat the system by logging into and using email accounts pwned in these breaches.

Totally agree with this. It's cool to have this data but people using shared VPNs and unique emails will be penalized.

Re: Pwned or Bot

#16
Wouldn't bad actors just push their fake email addressess to haveibeenpwned in fake leaks? Steps:

1- periodically set up a legitimate looking service, possibly proxying real services. 2- wait a year or two for your fake service to premiate throughout the www and for seach engines to index it. 3. Mix your bot email addresses with legitimate previously pwned addresses. 4- proclame "woe is me, for thyself hasth been pwned"

You can set up this process so that you can inject a couple 100k bot email addresses periodically every couple of months.

This is an incredibly shortsighted idea with the potential to hurt a lot of innocent people.

Re: Pwned or Bot

#17
post #2

Maybe I'm an outlier but the e-mail-adress I use for online payments or shops for over 10 years now has not been pwned. Maybe because I don't use this email for other sites where no money is involved or for social media. But I think hibp is not a great bot indicator.

[deleted]

Re: Pwned or Bot

#19

Facebook and Twitter are basically closed to new users. If you've gone this far without an account, your new one will be shut down for being a bot within hours of creating a new account, or flagged for "extra verification" which requires sending a government ID to these companies so they can verify that you didn't photoshop a fake government ID. This new approach seeks to extend this feature to the entire internet .…

   > so they can verify that you didn't photoshop a fake government ID.
Huh. How?

Re: Pwned or Bot

#20
post #7

> We're all so comprehensively pwned that if an email address isn't pwned, there's a good chance it doesn't belong to a real human.

GeekedIn: In August 2016, the technology recruitment site GeekedIn left a MongoDB database exposed and over 8M records were extracted by an unknown third party. The breached data was originally scraped from GitHub in violation of their terms of use and contained information exposed in public profiles, including over 1 million members' email addresses. Full details on the incident (including how impacted members can see their leaked data) are covered in the blog post on 8 million GitHub profiles were leaked from GeekedIn's MongoDB - here's how to see yours.

Compromised data: Email addresses, Geographic locations, Names, Professional skills, Usernames, Years of professional experience

Post reply on HN