Live data from Hacker News

Have I Been Pwned 2.0

troyhunt.com

221–230 of 323 posts

Re: Have I Been Pwned 2.0

#221

Like many people I have a "main" email address, and I use per-company addresses for almost everything else. Now that the domain-searches require subscriptions this site has become much less useful. I just added my domain to the site again and I see "2,243 Total Breached Addresses", and "18 Addresses excluding Spam Lists", but I have no idea what they are. Attempting to click the links shows me I need to "upgrade" to…

Is your per-company addresses a derivation of your main email address? If so, this is called “email tumbling” and services exist to strip the “per-company” part to expose your main email.

I can't speak for OP but I too use per-company or per-service emails, and no they have zero connection to my main email (not even the domain actually, domains are cheap so I have multiple ones for different purposes). Since I started doing so a very long time ago I did choose a standard scheme for it (making use of the company's domain), so it would certainly be possible to recognize it's a per-company domain given human attention or (more likely) AI. Ideally the email specifically would not be something I'd see but just a pointer that would be randomly/plausibly auto-generated, and then my email server (or client) could transparently disambiguate it via a db on my side to what the service was. Then it'd be undetectable. Unfortunately while it's clear enough how all the pieces of that could come together I don't know of any existing solution and haven't had time to try to hack on it myself. So far it hasn't given me any problems however.

Re: Have I Been Pwned 2.0

#222
post #209

Earlier quoted context omitted.

It's a sponsorship, so I'm not complaining, but if the goal was really to get people to use a password manager he would be sending them to Bitwarden since they have a free plan, plus their paid plan is only $10/year compared to $36 for 1Password.

Besides the pricing, is there any reason to prefer Bitwarden over 1Password? Been happily using 1Password for some years, never had any issues, but maybe I'm glossing over anything? Probably the cli interface (`op`) is the one feature I couldn't live without today.

Open-source versus proprietary and the option to self-host are the two that immediately come to mind.

Re: Have I Been Pwned 2.0

#223
post #3

Is there a term for this trend in web design, with defaulting to dark mode and having slick gradients everywhere?

The term is ‘unreadable’. There are good reasons `:prefers-color-scheme` exists; use it.

Re: Have I Been Pwned 2.0

#224

Earlier quoted context omitted.

We could also design some kind of electoral process for picking those in charge of defining the rules and creating yet more bodies to enforce it. Maybe this time we can come up with a better way to disincentivize corruption and bribery.

We could instead randomly select representatives instead of using popularity contests where the candidates need money for advertisements in order to get popular, or to just even let people know that they exist.[1] https://en.wikipedia.org/wiki/Sortition [1] But the real solution is getting rid of money.

Sure, that's still designing am electoral process. I didn't prescribe any one model in my precious comment.

Re: Have I Been Pwned 2.0

#225
When it mentions that your password has been leaked for a service, is this the plain text pwd (that service somehow stored that way) or is it a hash? Was the website salting the passwords (so no rainbow-table attack could happen)? What key derivation function were they using? Etc...

I feel the red circle with "Password compromised" is way too simplistic if this wants to be a TRUE trusty site regarding cybersecurity. If they just want to show fear and sell 1Password ads, I understand it, I won't consult it anymore. But if they want to really step up their game from a technical perspective, they should include more details.

Re: Have I Been Pwned 2.0

#226
Does it feel like this site is itself a vulnerability? It seems like being able to go type in anybody's email address and just get a list of sites where it was found would be part of an OSINT process.

Shouldn't it at least send you a link to verify that you control the address before showing your results?

Re: Have I Been Pwned 2.0

#227
post #130

Earlier quoted context omitted.

I regularly have doppelgangers that sign up for services with my email address. I've been added to door/visitor notifications. I have received medical information for them. Retirement package info. A telecom internal tracker. A Doubleclick account for a while. Lessons for their children. Countless rewards accounts.

This has literally never happened to me... is your email address "go@away.com" or something?

I also checked my throwaway gmail and it was included in a French Citizen leak [1]. I'm neither French, nor do I have any other connection to France. Not sure why my email would be included there, except for some random using my email (or misspelling theirs) – it's [5-7 letter english word][number] at gmail.

[1] https://haveibeenpwned.com/breach/FrenchCitizens

Re: Have I Been Pwned 2.0

#229

Does it feel like this site is itself a vulnerability? It seems like being able to go type in anybody's email address and just get a list of sites where it was found would be part of an OSINT process. Shouldn't it at least send you a link to verify that you control the address before showing your results?

[dead]

Re: Have I Been Pwned 2.0

#230

Earlier quoted context omitted.

"Microsoft Regional Director" We can debate semantics but if you describe yourself with a job title attached to a company then I suggest that you have an association which looks rather like ... employment.

Its not semantics at all, you just are excusing your own misunderstanding. He didn't describe himself with a job title, and he even explicitly states directly after listing those awards, that he is not an employee of Microsoft. Extending your logic, I have a CCIE, so if I ever state I'm a CCIE, I'm an employee of Cisco? I have a masters degree by coursework from a university, so I I ever state I have an Msc, I'm an e…

If I say "I'm a Cisco Regional Director" or "I'm a Walmart Regional Director" is you immediate though that I don't work for Cisco/Walmart?
Post reply on HN