Earlier quoted context omitted.
>This system would be more useful if it could report how these companies got my data. I want to know who betrayed me. The company might not have sold your info. They might have been hacked. There really isn't any way to know for sure FWICT.
I think he means why other five, presumably legitimate, companies have his email address when he never signed-up for them. My guess is it may be someone like Facebook who used to share "your friends' data" with third-party companies. So one of your friends, who may have your email, allowed a third-party company to get that list of his contacts (including your email) via the Facebook API (which at the time may have al…
Firefox Monitor
131–140 of 227 posts
Re: Firefox Monitor
#132Earlier quoted context omitted.
As topranks mentioned, all this data is already available and anyone could download it. However, in most leaks, you can't just use the information as the passwords are (hopefully) hashed/salted. That said, it is trivial to crack md5 if passwords are stored using that method. Also, not all leaks contain passwords, some might just be lists of email addresses or other information.
This is about making is easier to attack a particular person, but privacy concern. Breaks the anonymity on internet.
Re: Firefox Monitor
#133Earlier quoted context omitted.
As topranks mentioned, all this data is already available and anyone could download it. However, in most leaks, you can't just use the information as the passwords are (hopefully) hashed/salted. That said, it is trivial to crack md5 if passwords are stored using that method. Also, not all leaks contain passwords, some might just be lists of email addresses or other information.
This is about making is easier to attack a particular person, but privacy concern. Breaks the anonymity on internet.
Anything that anyone does after the fact is moot.
Re: Firefox Monitor
#134Disclaimer: Firefox Monitor dev here. Note: We just released a "V2" of the site that allows you to add multiple email addresses to monitor, and (then) to have all your breach alerts sent to your single primary email address.
I was able to add my first.m.last@gmail.com and firstmlast@gmail.com as separate emails.
I know that might complicate your detection system, it just might miss some breaches for people who use both.
Re: Firefox Monitor
#135Earlier quoted context omitted.
So, I 100% agree with you and think a sentence in multi-page privacy policy is not informed consent. Recently in EU GDPR regulation brought in some strict measures on how consent is requested and how data is shared and managed, I was delighted when websites started sending me emails asking me for content to market and share data. However I am now seeing a bunch of websites doing the shady tactic of showing a full pag…
Those don't meet the required standard of "an unambiguous indication by clear affirmative action" according to the UK ICO's interpretation of GDPR: https://ico.org.uk/for-organisations/guide-to-data-protectio... "You cannot rely on silence, inactivity, pre-ticked boxes, opt-out boxes, default settings or a blanket acceptance of your terms and conditions."
“You provided a contract, and I agreed even though I chose not to read it (despite you providing it), and used the service, but I didn’t really mean to agree” is the most ridiculous cop-out, in my view.
Re: Firefox Monitor
#136Earlier quoted context omitted.
I think he means why other five, presumably legitimate, companies have his email address when he never signed-up for them. My guess is it may be someone like Facebook who used to share "your friends' data" with third-party companies. So one of your friends, who may have your email, allowed a third-party company to get that list of his contacts (including your email) via the Facebook API (which at the time may have al…
Well, the legitimate companies could have been sold "leads" by other legitimate companies but the original source of the data could have been a hack.
Re: Firefox Monitor
#137Earlier quoted context omitted.
Well the have I been pwned website is also pretty trusted and is integrated into 1password. I don't know why Firefox wouldn't just integrate it into the browser like 1password did with their password manager. Would make more sense than just being a different front end to an existing site.
Pwned is not a standard english word. The vast majority of non-tech non-gamer non-under 40s are unfamiliar with this word but are familiar with firefox.
Re: Firefox Monitor
#138Earlier quoted context omitted.
You can use the + trick and . trick with Gmail addresses too. I think Outlook as well supports the + trick. The only downside to this is that there are plenty of sites that don't accept a + either knowingly or unknowingly.
this isn't a good anti-spam filter though. + addressing (even the fastmail kind) is trivial to parse and I'm 100% sure email harvesters are aware of it.
Re: Firefox Monitor
#139Earlier quoted context omitted.
I do this with Fastmail, including specialized subdomains to help me segment the addresses and then distinct email names for each sign up as necessary. You can also do something similar with Gmail (and probably other providers) using "+" in your username, e.g. "myname+hackernews@gmail.com". This creates a unique email address that delivers to your Gmail account as if the "+ " were absent. This is more easily defeated…
Using + isn't the best method as some services just won't allow having + sign in the email address (probably shitty email address detection) and of course spammers can simply strip the alias parts and send you mail. You'd have a better luck with *@user.your.domain if you can give each user a unique domain.
I bought a single domain @MyEmail.org, and create a new user for each site I sign up with that forwards to my gmail.
1@MyEmail.org, 2@MyEmail.org, 3@MyEmail.org etc...
Re: Firefox Monitor
#140Earlier quoted context omitted.
Fastmail supports this natively (and is awesome). You can do service@user.yourdomain.com and it will get delivered to user+service@yourdomain.com.
You can use the + trick and . trick with Gmail addresses too. I think Outlook as well supports the + trick. The only downside to this is that there are plenty of sites that don't accept a + either knowingly or unknowingly.