Live data from Hacker News

Have I been pwned? Check if your email has been compromised in a data breach

haveibeenpwned.com

241–250 of 294 posts

Re: Have I been pwned? Check if your email has been compromised in a data breach

#241
post #114

Earlier quoted context omitted.

I am surprised by how few people are aware of this: https://www.pwdhash.com/ Convenience provided via Chrome/Firefox extensions, portability provided by the website.

I second this. I've been using it for a few years now. It gives me great peace of mind knowing that my password on a site like HN is something like "e5wLoMB1kZ". I only have to remember a few passwords and yet each site has a unique password. Even in the event a leak of plain-text passwords I'm still secure in knowing that my other accounts won't be compromised unless there is a very determined attacker. However, you…

Yeah, I did not hear about pwdhash and it sounds like a nice idea.

One thing I have noticed though is that when one enters the same site password, you get the same "Hashed" password back to use. Yes, there is an extra step involved here so that buys you some security but I will be cautious in reusing site passwords.

Imagine an attack where for the top 100 sites in the world, all of the most commonly used passwords are used to generate the "Hashed" (pwdhash) passwords for each site and compile that info into a big list. This can then be added to the candidate list of password that can be tried in cracking leaked hashes.

The take way here is that even though pwdhash gives you domain-specific generated passwords, you will make to sure that you use a different site password as input to pwdhash for each site.

Re: Have I been pwned? Check if your email has been compromised in a data breach

#243
post #207

Earlier quoted context omitted.

...which does not really help without the crypto-key - even if you know a list of possible passwords you cannot test them.

Well, funnily enough, if you know your password and it was in the leak, you can test it against your own password.

lastpass.com/adobe will show you the list of hints of yourself and other users that used the password.

Re: Have I been pwned? Check if your email has been compromised in a data breach

#244
post #179

Is this a trap to build a mailing list? I tried a bunch of fake hotmail emails and 90% of them are "pwned". Very suspicious to say the least.

Aside from those who enter fake addresses or addresses they do not control, the folks who set up websites like this can also connect each email address with an IP address. This might be useful, e.g., for determining geolocation. It is sad to think that naive users are falling for this every time a data breach makes the news, handing over their email address to total strangers.

Re: Have I been pwned? Check if your email has been compromised in a data breach

#245
post #114
post #73

Earlier quoted context omitted.

This should be a lesson not to manage your own passwords, use a password manager there are many to choose from. I was also caught up in the Adobe breach but my password was randomly generated by my password manager.

I am surprised by how few people are aware of this: https://www.pwdhash.com/ Convenience provided via Chrome/Firefox extensions, portability provided by the website.

pwdhash uses a weak hashing mechanism, making it possible to brute-force master passwords. It is OK to use, but make sure that you have a cryptographically strong master password.

Re: Have I been pwned? Check if your email has been compromised in a data breach

#246
post #34

Normally wouldn't trust this, but: http://www.troyhunt.com/ http://www.intodns.com/haveibeenpwned.com (forwarded from haveibeenpwned.azurewebsites.net) http://www.whois.com/whois/haveibeenpwned.com Seems legit.

Troy Hunt has been blogging about this for a while. Troy is a good guy who blogs extensively on security matters. I don't see any risk in putting your details in here.

His recent posts on pwning peoples phones and tablets while they were at his conference talk are pretty amusing. Shows just how insecure things really are.

Re: Have I been pwned? Check if your email has been compromised in a data breach

#247
post #200

Feature request: allow wildcard searches, with a sufficiently large literal starting prefix, to return a simple "zero" or "more-than-one" result. EG: "john*@gmail.com" I'd then feel better about typing my address into a random site, and be able to check site-specific variants of my address more easily.

Also, for those of us that use aliases for each site we visit... it would allow a quick lookup of them.

Re: Have I been pwned? Check if your email has been compromised in a data breach

#249
post #117
post #97

Funny/scary anecdote I experienced a few days ago: most Linux flavors check against the cracklib database when changing passwords, and as I typed in an account password, a brand-new cracklib said it was based on a dictionary word. Now, my passwords are alphanumerical jumble, and they're usually comprised of an alphanumerical jumble "core" that I memorize and then a site-based or computer-based pre- and suffix. So, le…

whynotjustusereallylongpasswordsthatarehardformachinestocrack?

I've memorized an algorithm instead of trying to remember passwords. I don't actually remember hardly any of my passwords, instead I use this mini algorithm that I came up with to create unique passwords for each site I go to. Each time I go to a site it just takes me a couple seconds to figure out what the password is. I find it a lot easier to remember that one algorithm rather than trying to remember a bunch of passwords or rotating through the same few passwords.

Re: Have I been pwned? Check if your email has been compromised in a data breach

#250
post #111

Earlier quoted context omitted.

It took 120+ days for my ebay account to get deleted, but thankfully I could delete my paypal in only a few weeks.

The 120+ days thing with ebay is allegedly because they need to make sure any outstanding deals are closed and accounts settled. Of course that is absolute bullshit, it took them 120+ days to close my account and I had not used it for over 4 years at that point. They actually emailed me telling me that they were closing the account due to inactivity. They gave me 3 or 4 months to log on before it would be killed, so…

Common tactic as far as I can tell, other companies do the same thing. eg: My Blizzard account that I can't sign in to because it's cancelled has somehow been 'compromised' multiple times.
Post reply on HN