Live data from Hacker News

Firefox Monitor

monitor.firefox.com

191–200 of 227 posts

Re: Firefox Monitor

#191

Disclaimer: Firefox Monitor dev here. Note: We just released a "V2" of the site that allows you to add multiple email addresses to monitor, and (then) to have all your breach alerts sent to your single primary email address.

UI/UX complaint: on some breaches for one of my e-mails, I see entries saying "Compromised data: passwords". It's only slightly useful and makes me spend time searching reading the details. "Plaintext passwords" != "Unsalted password hashes" != "Salted password hashes". The qualifiers here would be immensely useful.

Also, what's with the cards here? I can't select any of the text on them.

Re: Firefox Monitor

#192
post #58

Mozilla really wants your information these days :(

This is a useful service that can help improve security for a lot of people. If you don't want to use it, fine, ... don't use it.

Re: Firefox Monitor

#193
post #2

How does this relate to HaveIBeenPwned.com? Is it a separate effort? Does it have more data? Is it built on top of their data? I've seen other services (like 1Password) just rely on HaveIBeenPwned because it's pretty solid – seems like it would be nice for the industry to coalesce around it and build these kinds of alerting features on top of it.

Love that site... current authentication manager I'm looking at will use their api for breach checking with the set/change password options.

Re: Firefox Monitor

#195

Earlier quoted context omitted.

Well, "legitimate". There's no legitimate reason for a company to remove anything from user-provided e-mail address.

Legitimate reason != legitimate company

Doing something like this is extra work, implying the company in question has either some malicious intent (e.g. spamming, or sharing data with third parties behind users' backs), misguided (e.g. thinking this is a proper way of dealing with user account spam), or just don't give a damn. Either one of these cases reflects badly on such company.

Re: Firefox Monitor

#196

Earlier quoted context omitted.

Legitimate reason != legitimate company

Doing something like this is extra work, implying the company in question has either some malicious intent (e.g. spamming, or sharing data with third parties behind users' backs), misguided (e.g. thinking this is a proper way of dealing with user account spam), or just don't give a damn. Either one of these cases reflects badly on such company.

You can reflect it however badly you want, I'm just saying these weren't companies most people would consider shady or cutoff business with over this issue.

Re: Firefox Monitor

#197
There are just so many problems.

Traditional authentication methods have failed us. I'm still waiting for a reasonable alternative, but the best we've come up with are things like 2FA and magic links?

Companies insist on sucking as much data out of their users as possible. What are your options? Hand over your personal information and give hackers a reason to attack your favorite services? Create a million different phone numbers, burner addresses, and fake personas? How exhausting.

Then there's the problem of treating data like SSNs, phone numbers, and legal names as private. These things could be public if central authorities could do their jobs correctly, but we've shifted the blame of e.g. "identity theft" to the end user who ultimately has no control over this stuff.

Further, official ID/passport/etc. scans are required of so many transactions and I guarantee my slumlord does not follow good security practices so what can I do other than sit like a duck? Monitors like this are a noble effort, and I'll definitely use them, but it sucks that it's come to this.

Re: Firefox Monitor

#198
post #135

Earlier quoted context omitted.

What kind of world do we live in where using a free service and agreeing to explicitly documented T&Cs doesn’t constitute acceptance? “You provided a contract, and I agreed even though I chose not to read it (despite you providing it), and used the service, but I didn’t really mean to agree” is the most ridiculous cop-out, in my view.

Firstly a Contract is a Meeting of Minds, the forty pages of small type in a PDF are nice, but it's laughable that you pretend you thought everybody read those before using your free service. And if they didn't read them, they clearly cannot agree with just every random term you threw in there and so it can't all be part of that meeting of minds, so there is not, in fact, a contract with people with those terms. OK,…

Is your issue that it’s 40 pages? Is your issue the font size?

What are the criteria that make terms by which one accesses a service irrelevant? At what point does the service provider’s consent not matter?

Your last paragraph seems to assume I am a service provider. I am not. I just think that people should be bound to the things to which they explicitly agree.

Does the “user must scroll to the bottom of the terms and tick a box affirming that they read and have agreed” serve as sufficient consent in your book?

Re: Firefox Monitor

#199
post #39

My email appears in six breaches. Only one of the companies I recognize. I have never done business with the other five. This pisses me off. Not that the data was stolen -- these things happen. It pisses me off that my data was shared with third parties without my knowledge or consent. And no, a paragraph buried in the basement of a privacy policy does not constitute informed consent. This system would be more useful…

For a major grocery chain with a Savers Card program, they wanted my name, phone number, etc. They claimed they would not not sell my data. I made up an imaginary name on the spot:

Joseph Kropholer

1. Six months later websites listed a Joseph Kropholer in my town. Unless I actually happened on a real name, they sold me out.

2. Reading the receipt for my name, the clerks in the check out line would thank me with "Thank you Mr Crap Hole-ermmmm. mumble mumble." Then they realize what they just called me. I did not intend that, but it is constantly funny.

Post reply on HN