Live data from Hacker News

Firefox Monitor

monitor.firefox.com

151–160 of 227 posts

Re: Firefox Monitor

#151
post #21

Apparently MyFitnessPal had their data breached, and my email address/password was in it. Checking my emails, I can't see anything from them about this. Loads of the usual marketing crap, but nothing about a breach. Not cool!

Same, for me it was them and Apollo. I can't find anything about either of them in my mail, but both claim to have notified their customers. That's very suspicious. I don't delete anything... Perhaps it found its way into my spam and got auto-deleted (entirely possible with Apollo, seems very unlikely with MFP).

Also got mine leaked from FitnessPal and Apollo and them only. No idea what Apollo is or how they got my stuff. Any idea what it is?

A link to each service's website would be awesome in the breach report on FireFox Monitor.

Re: Firefox Monitor

#152

Earlier quoted context omitted.

You can use the + trick and . trick with Gmail addresses too. I think Outlook as well supports the + trick. The only downside to this is that there are plenty of sites that don't accept a + either knowingly or unknowingly.

Yeah, that's why Fastmail has that syntax.

The + feature long predates gmail. Here’s an example description from the 1990s http://www.faqs.org/faqs/mail/addressing/index.html

Re: Firefox Monitor

#153
post #135

Earlier quoted context omitted.

Those don't meet the required standard of "an unambiguous indication by clear affirmative action" according to the UK ICO's interpretation of GDPR: https://ico.org.uk/for-organisations/guide-to-data-protectio... "You cannot rely on silence, inactivity, pre-ticked boxes, opt-out boxes, default settings or a blanket acceptance of your terms and conditions."

What kind of world do we live in where using a free service and agreeing to explicitly documented T&Cs doesn’t constitute acceptance? “You provided a contract, and I agreed even though I chose not to read it (despite you providing it), and used the service, but I didn’t really mean to agree” is the most ridiculous cop-out, in my view.

Firstly a Contract is a Meeting of Minds, the forty pages of small type in a PDF are nice, but it's laughable that you pretend you thought everybody read those before using your free service. And if they didn't read them, they clearly cannot agree with just every random term you threw in there and so it can't all be part of that meeting of minds, so there is not, in fact, a contract with people with those terms.

OK, so what _was_ agreed? Well, a court is going to decide what a _reasonable_ person thought they were getting into, and they'll use legislation (such as that from the GDPR) to help decide that. They'll also keep in mind a theory about relative power. You wrote these T&Cs, so the court is going to conclude that you should have taken that opportunity to add any terms you really cared about. On the other hand the _user_ wasn't able to edit the terms, so really anything they reasonably expected should probably be acceptable.

The GDPR says that you need to have the user explicitly opt in, they get to reasonably assume that's how it works, you can't change that in the text they didn't read.

You might think, "Aha, but I made them check a box saying they agree they read it". Too bad, that doesn't help for a very simple and pragmatic reason:

Judges are people too. When you explain this theory to a judge, who like other people has had to check loads of these stupid "I agree I have read a 400 page document before using this free service" boxes, they are going to look at you like you just said you think they're an idiot.

If you're thinking maybe you can try this on and see for yourself, you'll probably have to be your own lawyer. Certainly in the UK no competent lawyer will take that work. Years ago the UK passed a law banning certain contract terms in "short" residential leases (a "short" lease would be e.g. renting a house for a year). Immediately scumbag landlords wrote new contracts that said basically "I, the under-signed, agree to these terms even though they're not allowed" and then demanded their tenants sign the revised contract instead. Judges were not happy, and I pity the fool who first appeared in front of a judge trying to argue that this was somehow legal when it's obviously not.

If you're so sure your users want to explicitly agree to let you do this, make it a separate opt-in, like the regulation says. When, to your disappointment, they don't want to, that is a _learning opportunity_ for you. Take it.

Re: Firefox Monitor

#154

Disclaimer: Firefox Monitor dev here. Note: We just released a "V2" of the site that allows you to add multiple email addresses to monitor, and (then) to have all your breach alerts sent to your single primary email address.

Looks nice, thanks. Why do I need a Firefox account to monitor my email?

Re: Firefox Monitor

#155
post #10

Mozilla and Apple, lately, are the only companies I trust my data to. Nice to see more from both.

I do not think you understand the meaning of the word "trust", you may want to look it up.

Or maybe you were born after firefox deactivated all add-ons by surprise and accident?

Maybe you haven't thought through what an 'app store' really is?

Whatever the case, don't bother interacting with me you are so far behind I know nothing you have to say will be of any value on the topics of 'trust', 'corporation' or 'privacy.'

Re: Firefox Monitor

#156
post #44

This is basically a frontend for haveibeenpwned. Creating it costed Mozilla money. Why did they do this instead of linking directly to the original page?

I don't know, but they are going to have to find something to do with all of those email addresses in a database connected to the source vectors.

btw: the nsa tracks people by email address, as in, according to snowden, that is an often used search term to pull up all the surveilled data on an individual.

/s

Re: Firefox Monitor

#157
post #57

Are they doing anything with the email addresses beyond checking they appear in breach databases ? Are they anonymizing things, for example using some kind of one-way hash to match email addresses ? Is it GDPR-compliant ? There is not clear explanation of how they're processing that data as there should be as email addresses are personal information.

They have the fish in the barrel, so I am figuring that this is the next step in that process.

The fish who have any chance of escaping the barrel will likely be attracting the most attention...and other things.

Re: Firefox Monitor

#158
post #94

Earlier quoted context omitted.

Browsers have tons of feature; you don't need to use the ones you don't care for. It's trivial to remove the pocket button - right-click and select "remove from address bar". If I might ask - how is a "save to pocket" intrusive? This isn't like any of the billions of social media buttons you'll come across on the web; it's not a tracker or anything (and if you do click it, you're going to need to make an account firs…

It's intrusive because it takes up space on my screen, and because it's completely useless without a Pocket account. Thanks for the tip about removing it from my address bar. Done. It still shows up second in the dot menu, but it's an improvement. I'd rather it were an extension that was installed by default that I could uninstall.

This isn't at all discoverable, but... https://support.mozilla.org/en-US/kb/disable-or-re-enable-po...

Re: Firefox Monitor

#159
post #58

Mozilla really wants your information these days :(

The other response to this is...wow, 'all they have is your email address'

snowden: 'all i needed was your email address to pull pull up all your entire surveillance record'

hackernews: propaganda shilling? never heard of it.

Re: Firefox Monitor

#160
post #42
post #32

Earlier quoted context omitted.

I find spycloud a lot more useful as website tbh. They at least tell you explicitly which passwords were leaked.

How does the password matter though? Won’t it usually be some hashes anyway and if you are breached you should just change your password anyway.

Some bad guys (and it doesn't have to be many) specialise in taking credentials that were leaked (e.g. "bob@example.com has password Superman45") and trying them on every service they can to "crack" more accounts. This is called "Credential stuffing".

Since this can be heavily automated the returns don't need to be large. e.g. maybe you can spend $100 and crack 5000 accounts with a new site that's suddenly hot, you sell one of them with a cool name to some Russian wannabe-star for $50 and the rest to spammers for 10¢ each (you don't care why spammers want stolen accounts, trust me they do though), you just made $450 for almost no effort.

If you use unique passwords everywhere, you don't need to care very much. But most people do not do this. If you _mostly_ use unique passwords, but er, actually your Twitter, a PHP forum you used back in 2010 and your iTunes account all have the same password, when that PHP forum gets hacked credential stuffing means your Twitter and iTunes will soon be raided.

If the site used a _good_ hash, it buys you time in proportion to a combination of how good your password was (how much entropy) and how good the hash was (how expensive hash trials are, multiplied by how much salt was used). If your password was "pass1234" then no matter how great a hash was used, I can guess it was "pass1234" and be correct instantly. If your password was 24 random alphanumerics then even a crap hash like MD5(password) is safe.

Post reply on HN