Earlier quoted context omitted.
Because the Mozilla brand is more trusted than a random website with ‘Pwned’ in its name. Also, it's being built into Firefox so having a website for it too seems like a good idea.
Well the have I been pwned website is also pretty trusted and is integrated into 1password. I don't know why Firefox wouldn't just integrate it into the browser like 1password did with their password manager. Would make more sense than just being a different front end to an existing site.
Firefox Monitor
121–130 of 227 posts
Re: Firefox Monitor
#122I checked my email address and it says my data was lost by verifications.io. I've never heard of that site before and going there didn't reveal any clues. I googled the name and found a report [1] on the breach. They lost control of records on 2 billion email addresses. [1]: https://www.forbes.com/sites/daveywinder/2019/03/10/2-billio...
From your linked article: "This company validates bulk email lists for companies wanting to remove inactive addresses from newsletter mailouts."
Re: Firefox Monitor
#123Earlier quoted context omitted.
Fastmail supports this natively (and is awesome). You can do service@user.yourdomain.com and it will get delivered to user+service@yourdomain.com.
As does Gmail. But not all services supports the + on login forms. I believe this was part of the email standard?
But yes, that's why Fastmail supports the alternative syntax.
Re: Firefox Monitor
#124Disclaimer: Firefox Monitor dev here. Note: We just released a "V2" of the site that allows you to add multiple email addresses to monitor, and (then) to have all your breach alerts sent to your single primary email address.
Still, great job!
Re: Firefox Monitor
#125Earlier quoted context omitted.
Fastmail supports this natively (and is awesome). You can do service@user.yourdomain.com and it will get delivered to user+service@yourdomain.com.
You can use the + trick and . trick with Gmail addresses too. I think Outlook as well supports the + trick. The only downside to this is that there are plenty of sites that don't accept a + either knowingly or unknowingly.
Re: Firefox Monitor
#126My email appears in six breaches. Only one of the companies I recognize. I have never done business with the other five. This pisses me off. Not that the data was stolen -- these things happen. It pisses me off that my data was shared with third parties without my knowledge or consent. And no, a paragraph buried in the basement of a privacy policy does not constitute informed consent. This system would be more useful…
>This system would be more useful if it could report how these companies got my data. I want to know who betrayed me. The company might not have sold your info. They might have been hacked. There really isn't any way to know for sure FWICT.
My guess is it may be someone like Facebook who used to share "your friends' data" with third-party companies. So one of your friends, who may have your email, allowed a third-party company to get that list of his contacts (including your email) via the Facebook API (which at the time may have allowed this sort of sharing).
Even today, a ton of Android, and until more recently iOS, apps would collect your contact list, which means YOU shared your friends' phone numbers with some random app company. I imagine many of those friends would be pissed off at you for allowing their phone numbers to fall into the wrong hands, too, and now getting spammed all the time (if only they knew how the spam companies got their phone numbers to begin with).
Re: Firefox Monitor
#127would be a lot more helpful if it clarified if it's hashed passwords or plaintext, also if they were hashed with a site-wide salt or per-user salt. imo, this distinction is too important to be omitted from a short summary.
Re: Firefox Monitor
#128Disclaimer: Firefox Monitor dev here. Note: We just released a "V2" of the site that allows you to add multiple email addresses to monitor, and (then) to have all your breach alerts sent to your single primary email address.
Just signed up, and it send breach notifications to individual emails, not the main one... Still, great job!
But future breach alerts will be sent to the Primary address. (If you select that in your preferences.)
Re: Firefox Monitor
#129Earlier quoted context omitted.
Fastmail supports this natively (and is awesome). You can do service@user.yourdomain.com and it will get delivered to user+service@yourdomain.com.
You can use the + trick and . trick with Gmail addresses too. I think Outlook as well supports the + trick. The only downside to this is that there are plenty of sites that don't accept a + either knowingly or unknowingly.