Live data from Hacker News

Firefox Monitor

monitor.firefox.com

161–170 of 227 posts

Re: Firefox Monitor

#161
Sometimes I wonder if it would be easier if we just start anew. I cant go back and change every single password with that email address that I didn't use KeyChain before.

Re: Firefox Monitor

#163

Disclaimer: Firefox Monitor dev here. Note: We just released a "V2" of the site that allows you to add multiple email addresses to monitor, and (then) to have all your breach alerts sent to your single primary email address.

Would it be possible to handle email addresses with the + trick?

E.g. you can supply your email address as foo+bar@ and mail sent to that address will be routed to foo@ by some providers like gmail and protonmail.

But then that means enumerating every + address you use (I almost exclusively do this).

Thoughts? I know this came up in a HIBP forum and I think Troy Hunt took the position of too much work for 0.1% of users, many of whom are likely technical enough to use a password manager and do this enumeration if they wanted.

Re: Firefox Monitor

#164
post #39

My email appears in six breaches. Only one of the companies I recognize. I have never done business with the other five. This pisses me off. Not that the data was stolen -- these things happen. It pisses me off that my data was shared with third parties without my knowledge or consent. And no, a paragraph buried in the basement of a privacy policy does not constitute informed consent. This system would be more useful…

>does not constitute informed consent.

Most contracts that keep modern day businesses running work by pretending uninformed consent counts as consent. If we required true informed consent things would grind to a halt. Which may not be a bad thing.

Re: Firefox Monitor

#165

Earlier quoted context omitted.

This isn’t to prevent spam, it is to identify the original leak. If the unique email address you gave to company X is used for solicitations by company Y, company X must have given it away.

Then what?

If you live in Europe, you might have a case.

Re: Firefox Monitor

#166
post #142

Earlier quoted context omitted.

You can also do this with a single email address and the + symbol: jimmy+facebook@gmail.com jimmy+twitter@gmail.com jimmy+hackernews@gmail.com all go to jimmy@gmail.com

Does a . works as well doesn't it? I can't remember if it gets stripped out or not if the email server isn't expecting it.

Gmail explicitly ignores '.' in email addresses. I don't think it's standard behaviour across other email systems, though, and even gmail didn't always ignore it.

Re: Firefox Monitor

#167

Earlier quoted context omitted.

This isn’t to prevent spam, it is to identify the original leak. If the unique email address you gave to company X is used for solicitations by company Y, company X must have given it away.

Then what?

I usually go for @example.com where is the company I’m handing my address to. After a breach I route that address to /dev/null

Re: Firefox Monitor

#169

Disclaimer: Firefox Monitor dev here. Note: We just released a "V2" of the site that allows you to add multiple email addresses to monitor, and (then) to have all your breach alerts sent to your single primary email address.

Are there any plans of including Monitor directly into the browser?

Re: Firefox Monitor

#170

I checked my email address and it says my data was lost by verifications.io. I've never heard of that site before and going there didn't reveal any clues. I googled the name and found a report [1] on the breach. They lost control of records on 2 billion email addresses. [1]: https://www.forbes.com/sites/daveywinder/2019/03/10/2-billio...

It sounds like this was email addresses only, and they're very shady about how they acquired this information in the first place. "The real question that the researchers and Troy Hunt, founder of Have I Been Pwned?, want to know is how Verifications.io got its hands on all of this information in the first place. The Estonian-based company has refused to respond to questions from different news outlets and has taken d…

The premise of the company explains how they got the information. Marketing teams at hundreds of other companies sending over their lists to the site to see if some of their emails are fake.
Post reply on HN