Live data from Hacker News

Firefox Monitor

monitor.firefox.com

111–120 of 227 posts

Re: Firefox Monitor

#111
post #11

Looks like this doesn't include another feature of HaveIBeenPwned. Its cracked password hash database. If you trust their JavaScript, you can type in your passwords and see if they are on the list. If you're a little more paranoid you can download the hashes and do your own search.

Well with the API it’s pretty easy to test your password. You just have to hash it, send the 5 first characters and it returns the list of the hashes starting with those 5 characters. You then just check.

It's easy if you know what you're doing. I don't think my mother could do this.

Re: Firefox Monitor

#112
post #69
post #30

Earlier quoted context omitted.

Not everything needs to be a "big tech company", but you are right big tech companies are quite similar in this respect. At critical mass capitalism seems to cause companies to lose their driving principles that made them unique - their behaviour becomes more of a mindless ecology driven solely by money. Now look at Mozilla, it's a non profit, look at everything it does, they have never lost their principles. They wi…

> Now look at Mozilla, it's a non profit, look at everything it does, they have never lost their principles. I take issue with this. Mozilla has a corporate arm and they're the ones in control of Firefox marketing and development. Take for example the fact that they were (most likely) paid to install an extension to advertise a TV show. Apple has yet to display any ads to me on my Mac, unlike Microsoft in Windows. I…

That's just for legal reasons. Profits from the Corporation are put in to the Foundation. There are no shareholders making money.

Mozilla weren't paid for Mr Robot. Their finances are made public.

Re: Firefox Monitor

#113

I checked my email address and it says my data was lost by verifications.io. I've never heard of that site before and going there didn't reveal any clues. I googled the name and found a report [1] on the breach. They lost control of records on 2 billion email addresses. [1]: https://www.forbes.com/sites/daveywinder/2019/03/10/2-billio...

I had similar with a website called Apollo. Story linked below[1]. Edit: Their opt out page and main site[2]. Notably, Firefox Developer Edition warned me and linked me to the main Firefox Monitor page, so it's something that's being built into Firefox. [1] https://www.wired.com/story/apollo-breach-linkedin-salesforc... [2] https://www.apollo.io/privacy-policy/

Interesting, thanks for linking the story. I also had the same experience with Apollo.

Its frustrating since I never signed up for their services, and I have no control over who my data is sold to... Its getting to the point where I just assume all my data is pwned, and change passwords frequently

Re: Firefox Monitor

#114

I checked my email address and it says my data was lost by verifications.io. I've never heard of that site before and going there didn't reveal any clues. I googled the name and found a report [1] on the breach. They lost control of records on 2 billion email addresses. [1]: https://www.forbes.com/sites/daveywinder/2019/03/10/2-billio...

I wonder how I can send them my GDPR request. Any ideas?

Re: Firefox Monitor

#115

So basically if I put somebody's email address I could know the sites they have logged in in the past? And then I can use the leak and get access to their account? Shouldn't this information be mailed to the email address queried rather than displaying upfront

As topranks mentioned, all this data is already available and anyone could download it. However, in most leaks, you can't just use the information as the passwords are (hopefully) hashed/salted. That said, it is trivial to crack md5 if passwords are stored using that method. Also, not all leaks contain passwords, some might just be lists of email addresses or other information.

This is about making is easier to attack a particular person, but privacy concern. Breaks the anonymity on internet.

Re: Firefox Monitor

#116
post #55
post #39

My email appears in six breaches. Only one of the companies I recognize. I have never done business with the other five. This pisses me off. Not that the data was stolen -- these things happen. It pisses me off that my data was shared with third parties without my knowledge or consent. And no, a paragraph buried in the basement of a privacy policy does not constitute informed consent. This system would be more useful…

> I want to know who betrayed me. You can run your own email server (or have a company host a private domain for you), set up a catch-all address that only you know, then use a different email address for every site you sign up to. That way you can find out this sort of information. Using this technique, I know for example that spammers obtained the address I signed up to Stack Overflow with. The email is not shown o…

This is what I've done for close to 15 years and I'm generally surprised by how few of my address have been leaked.

Re: Firefox Monitor

#117
post #55

Earlier quoted context omitted.

> I want to know who betrayed me. You can run your own email server (or have a company host a private domain for you), set up a catch-all address that only you know, then use a different email address for every site you sign up to. That way you can find out this sort of information. Using this technique, I know for example that spammers obtained the address I signed up to Stack Overflow with. The email is not shown o…

Fastmail supports this natively (and is awesome). You can do service@user.yourdomain.com and it will get delivered to user+service@yourdomain.com.

You can use the + trick and . trick with Gmail addresses too. I think Outlook as well supports the + trick. The only downside to this is that there are plenty of sites that don't accept a + either knowingly or unknowingly.

Re: Firefox Monitor

#118
post #55
post #39

My email appears in six breaches. Only one of the companies I recognize. I have never done business with the other five. This pisses me off. Not that the data was stolen -- these things happen. It pisses me off that my data was shared with third parties without my knowledge or consent. And no, a paragraph buried in the basement of a privacy policy does not constitute informed consent. This system would be more useful…

> I want to know who betrayed me. You can run your own email server (or have a company host a private domain for you), set up a catch-all address that only you know, then use a different email address for every site you sign up to. That way you can find out this sort of information. Using this technique, I know for example that spammers obtained the address I signed up to Stack Overflow with. The email is not shown o…

I believe they were breached relatively recently. If your jurisdiction doesn't require reporting you might not have gotten notification currently or in the past. They may also not know they're breached.

Reach out to support.

Re: Firefox Monitor

#119
post #55

Earlier quoted context omitted.

> I want to know who betrayed me. You can run your own email server (or have a company host a private domain for you), set up a catch-all address that only you know, then use a different email address for every site you sign up to. That way you can find out this sort of information. Using this technique, I know for example that spammers obtained the address I signed up to Stack Overflow with. The email is not shown o…

Fastmail supports this natively (and is awesome). You can do service@user.yourdomain.com and it will get delivered to user+service@yourdomain.com.

As does Gmail. But not all services supports the + on login forms.

I believe this was part of the email standard?

Post reply on HN