Live data from Hacker News

The 773M Record “Collection #1” Data Breach

troyhunt.com

121–128 of 128 posts

Re: The 773M Record “Collection #1” Data Breach

#121
post #3

This is frankly terrifying and very ironic. Websites put so much effort into tracking every little thing about their users, from where they come from to what they do. Hotjar ( https://hotjar.com ) goes ahead and tracks mouse movements and now we even have crazy f-ed up startups like Peekmap ( https://peekmap.com ) that claim to predict eye gaze without the webcam. And yet they get pwned so easily. So much effort into…

You should provide the map on the homepage in real-time, otherwise I won't believe it

Re: The 773M Record “Collection #1” Data Breach

#123
post #60

Earlier quoted context omitted.

We are getting there, thanks to the EU. The GDPR directive has teeth, and it /will/ affect all larger US companies as well. Fines of up to 4% of yearly revenue area no joke: https://www.forbes.com/sites/bernardmarr/2018/06/11/gdpr-the...

Have there been any notable cases of actual enforcement GDPR enforcement yet?

Only small fry. Knuddels, a German chat platform, was fined for a data breach and storing passwords unencrypted.

But data protection institutions are warming up for taking Facebook to task: https://www.cnbc.com/2018/10/04/facebook-data-breach-top-eu-... - the 1.6bn is way over the top since FB informed customers in time, but still this will be a lighthouse case.

Re: The 773M Record “Collection #1” Data Breach

#124
post #52

Earlier quoted context omitted.

He has the "Pwned Password" search to allow you to narrow it down and he has a really good article that he links to explaining why despite its inconvenience. If I was him I'd do the same. HIBP is a side project of his and I wouldn't be able to sleep at night knowing I have the responsibility of securing billions of email & password combinations. At the risk of the breach of those accounts adding fuel to the credentia…

I am not sure you should put too much confidence in the "pwned password" search. I know one of the weak password I stupidly reuse everywhere was compromised since I had someone buy something with my paypal account. But it comes up as clean in the password search. So it was probably cracked from one of the leaked hashes but the plain text was never entered into the public dumps.

It would be impossible for the site to have every password ever compromised.

It can only check against a database of known password leaks.

Re: The 773M Record “Collection #1” Data Breach

#127

Earlier quoted context omitted.

You’re welcome, it may be an interesting social experiment to watch

FWIW, this comment was not made by me, the creator of this account.

We've banned this account. Please don't do signal/noise-destroying tricks on HN.

If you want the account unbanned, feel free to email hn@ycombinator.com with evidence that you own it and a promise not to do stuff like this.

Re: The 773M Record “Collection #1” Data Breach

#128

Earlier quoted context omitted.

You’re welcome, it may be an interesting social experiment to watch

FWIW, this comment was not made by me, the creator of this account.

Download torrents of collections 1, 2, etc. https://satoshibox.com/ggywi8ikt4e5kdrs24yu2soy
Post reply on HN