Live data from Hacker News

Authentication and the Have I Been Pwned API

troyhunt.com

111–120 of 125 posts

Re: Authentication and the Have I Been Pwned API

#111

Earlier quoted context omitted.

Yeah, the availability of the data being common rather than rare, so the skill of collecting that data doesn't create a power structure where only the hackers/skilled users have power. Imagine it being $500/month to access HIBP, because that's the alternative, not some, "everyone agrees to only use this info for good".

Explain to me how anybody besides myself can use info about my leaked account for something good or useful. I can’t think of an example. Therefore, having that info cost more is better. Having it cost a lot more is a lot better. (I’m assuming I can still get access for free by having provided directly to my email address.)

A service provider could check the API for the signup email and if previously compromised could challenge the signup with additional CAPTCHA steps to detect bot activity. They could check email+PW entered against leaked pairs and prevent you from registering with a known-compromised PW.

Your bank could check emails attached to customer accounts and work with affected customers to ensure their bank account access is secure.

You employer could check for leaks of accounts using corporate domains. They could check leaked passwords against known last 5 to see if there are active threats.

Re: Authentication and the Have I Been Pwned API

#112
post #75

Earlier quoted context omitted.

There's a difference - he's not selling the leaked passwords. He's selling the information that a password has been leaked for a certain account. You can't buy stolen passwords from the site, so it's perfectly legal.

I don't think it is that clear -- he is selling access to a data set containing PII (email address or account names). Its stolen data. One can make a case that free and open access to this data set is a common good, however once money is involved, one is conducting business with data that one did not legally obtain. It is not 'perfectly legal'.

I don’t think the API ever returns that information. You need to already have the email address to be queried.

Re: Authentication and the Have I Been Pwned API

#114

Who bruteforce scrapes the HIBP API across many IP addresses when they could just download the original leaked username & password databases? Theres even a torrent file of all of them I won't link here...

Torrent file Of ALL leaks? I usually only see some And when people ask about a latest leak, others disingenuously reply “just check YOUR email on HIBP what kind of person needs the database”

If you run a web service and want to proactively expire breached passwords, you need to have full list of plain-text passwords to hash them with algorithm you are using (and use the same salt if you are doing that too).

Re: Authentication and the Have I Been Pwned API

#115

Earlier quoted context omitted.

It's not that clear cut unfortunately. What do you really know about Troy and his service? Really just what he wants you to know. For example, Troy stores extremely valuable information about millions of people without their consent. A lesbian women in the Arabs, who might have had her credentials breached on a gay forum, who also has a gambling addiction and had her password breached on a gambling website and on ano…

I am trying to assume good faith, but I confess to being incredibly confused by this post. I just skimmed the last two months of Troy’s tweets (which constitutes quite a few — he is prolific) and couldn’t find a _single_ one that matches up with any of your summations. Would you mind showing your work?

I'm wondering whether (deliberately or accidentally) dustinmorris pulled up the wrong Twitter profile or something. No part of his description seems to me like it has any connection with reality.

Re: Authentication and the Have I Been Pwned API

#116

Earlier quoted context omitted.

Yeah, the availability of the data being common rather than rare, so the skill of collecting that data doesn't create a power structure where only the hackers/skilled users have power. Imagine it being $500/month to access HIBP, because that's the alternative, not some, "everyone agrees to only use this info for good".

Explain to me how anybody besides myself can use info about my leaked account for something good or useful. I can’t think of an example. Therefore, having that info cost more is better. Having it cost a lot more is a lot better. (I’m assuming I can still get access for free by having provided directly to my email address.)

What? No, you're not understanding. Even if no one but you could use this info legitimately, the fact that it's widely available depowers the people who have the skills to collect it (specifically, people who want to do you harm).

By virtue of the fact that this info is widespread, you have no choice but to take actions to protect yourself from this information. That means the information becomes useless.

You are, in a way, being shamed into acting, through public disclosure. So no, having that info cost is not more better, it's more worse.

Furthermore, it is not an option to only let you have this information. That ship sailed when the breaches happened. You don't get access to this information for free, you don't get to control the dissemination of this information, you are powerless. You're acting like HIBP is the only way people can find this info out; it's not. That $500 price tag is just for you. People who are more skilled than you or I at collecting this info get it for free, and that's never going away.

Re: Authentication and the Have I Been Pwned API

#117

Earlier quoted context omitted.

Explain to me how anybody besides myself can use info about my leaked account for something good or useful. I can’t think of an example. Therefore, having that info cost more is better. Having it cost a lot more is a lot better. (I’m assuming I can still get access for free by having provided directly to my email address.)

What? No, you're not understanding. Even if no one but you could use this info legitimately, the fact that it's widely available depowers the people who have the skills to collect it (specifically, people who want to do you harm). By virtue of the fact that this info is widespread, you have no choice but to take actions to protect yourself from this information. That means the information becomes useless. You are, in…

You can’t have it both ways. Either it’s widely available, or it isn’t.

If it’s already widely available then HIBP doesn’t accomplish anything. (It doesn’t anyway, since it doesn’t “shame” anybody except people who are already signed up, who only need and get their own info.) If it isn’t widely available then HIBP is helping people who are bad at collecting and using this information to do so.

We accept that from bug reports only because of the other benefits that come from releasing the info.

Re: Authentication and the Have I Been Pwned API

#118

Earlier quoted context omitted.

What? No, you're not understanding. Even if no one but you could use this info legitimately, the fact that it's widely available depowers the people who have the skills to collect it (specifically, people who want to do you harm). By virtue of the fact that this info is widespread, you have no choice but to take actions to protect yourself from this information. That means the information becomes useless. You are, in…

You can’t have it both ways. Either it’s widely available, or it isn’t. If it’s already widely available then HIBP doesn’t accomplish anything. (It doesn’t anyway, since it doesn’t “shame” anybody except people who are already signed up, who only need and get their own info.) If it isn’t widely available then HIBP is helping people who are bad at collecting and using this information to do so. We accept that from bug…

You're not getting that the alternative is much worse.

Your data is out there. Period. The end. You don't have control over that. All you're doing is trying to re-establish control over data you already lost.

The question now is, do you want it only in the hands of people who want to harm you, or do you want it in the hands of both people who want to harm you as well as people who want to help you?

You seem to only want bad guys to have your data. That's weird.

Re: Authentication and the Have I Been Pwned API

#119

Earlier quoted context omitted.

You can’t have it both ways. Either it’s widely available, or it isn’t. If it’s already widely available then HIBP doesn’t accomplish anything. (It doesn’t anyway, since it doesn’t “shame” anybody except people who are already signed up, who only need and get their own info.) If it isn’t widely available then HIBP is helping people who are bad at collecting and using this information to do so. We accept that from bug…

You're not getting that the alternative is much worse. Your data is out there. Period. The end. You don't have control over that. All you're doing is trying to re-establish control over data you already lost. The question now is, do you want it only in the hands of people who want to harm you, or do you want it in the hands of both people who want to harm you as well as people who want to help you? You seem to only w…

Thanks for the explanation. I get your point now. I did not find BFDM’s proposed benefits from white hats having access to be compelling. So what I’m struggling with is simply the idea that anybody could do something good with my data. If only bad can be done, then the fewer people spreading the data around, the better. Your presupposition is that some people will do good with it if they have access that currently only bad people have. Can you give an example of one of some of those good things?

Re: Authentication and the Have I Been Pwned API

#120

Earlier quoted context omitted.

You're not getting that the alternative is much worse. Your data is out there. Period. The end. You don't have control over that. All you're doing is trying to re-establish control over data you already lost. The question now is, do you want it only in the hands of people who want to harm you, or do you want it in the hands of both people who want to harm you as well as people who want to help you? You seem to only w…

Thanks for the explanation. I get your point now. I did not find BFDM’s proposed benefits from white hats having access to be compelling. So what I’m struggling with is simply the idea that anybody could do something good with my data. If only bad can be done, then the fewer people spreading the data around, the better. Your presupposition is that some people will do good with it if they have access that currently on…

1Password tells you which of your passwords have been part of a breach. Many other companies will suspend the accounts of anyone whose login information to their leaked as part of another site's breach.

Other websites won't allow you to use a password that's listed as a common password from the aggregated passwords in breaches.

Lots of studies have been done on password frequency, such as the top 100 most common passwords and what security people can do about their repeated use.

Based on your question however, I'm concerned you don't actually get my point. You're being forced into action, exactly how companies are forced into action, by the availability of this information. You have to change your password if it's easily available to anyone who uses this API and who has your email address, you no longer get to pretend it's not a big deal.

Post reply on HN