Live data from Hacker News

Have I Been Pwned 2.0

troyhunt.com

271–280 of 323 posts

Re: Have I Been Pwned 2.0

#271
post #262

Earlier quoted context omitted.

Remind me what CCIE stands for? I don't think many people would be confused into thinking a Microsoft Certified Application Developer or an AWS Certified Cloud Practitioner are actually employees of those particular companies

Yes, those are better names. That doesn't make him a Microsoft employee.

I'm not saying it makes him an employee. I'm saying those are bad attempts to argue that it's not a confusing title.

Re: Have I Been Pwned 2.0

#272
post #22

He should partner with a law firm, for class action lawsuits, for every breach due to negligence (which is probably all of them). Tie in to a banking service, so you can do direct deposits to many millions of people, every time there's new settlements paid, and you'll be a folk hero. Get lawyers who want negligent companies to actually regret the breaches, with judgements that hurt. (Rather than a small settlement th…

Ah yes, automated lawsuit initiation, that's what we need! Ooh, we could run every breach announcement through Deep Research and let the AI make a determination on which one is negligence! That would definitely incentivize more transparency and accountability on behalf of companies! Actually no, the end result of this will be a return to deny, deny, deny, because the worst case scenario then becomes the truth getting…

Look at this recent “data incident”

https://oag.ca.gov/system/files/Partnership%20HealthPlan%20o...

“Based on the investigation into this incident, it was determined that the information involved may include your name, Social Security number, date of birth, Driver’s License number (if provided), Tribal ID number (if provided), medical record number, treatment, diagnosis, prescription and other medical information, health insurance information, member portal username and password, email address, and address.”

It’s not about innocence or guilt. If you leak so much information these people will have to monitor every single account, credit card, etc for life, on top of all their personal sensitive info being leaked and possibly accessed by unscrupulous employers. The damage is incredible. It’s not about innocence. It’s about responsibility.

Re: Have I Been Pwned 2.0

#274

Earlier quoted context omitted.

The fact that you think random middle managers are all that psychopathic really says more about you than it does some hypothetical middle manager. Are their psychopaths and Machiavellian schemers in management? Certainly. Are they the majority? Almost certainly not, unless you're working for absolutely the wrong company. As the Brits would say, "cock-up before conspiracy."

No. It may not be conscious Machiavellian scheme, but it's a common attitude among middle managers. They are extremely sensitive to their reputation, which is why they punish people who make them look bad, even if it's something good for the company. Finding security vulnerabilities or wasted resources is met with an ambiguous hostility. And unfortunately, a lot of people aren't emotionally intelligent enough to reco…

Everyone is extremely sensitive to their reputation. That is just human nature. Someone who can't factor that into their actions and communications is frankly lacking basic social skills.

Re: Have I Been Pwned 2.0

#275
post #254

Earlier quoted context omitted.

How does the EU solution make user's whole? At least with class actions, users get to see a few pennies. I'm not trying to make an argument against strong regulatory bodies. We need those for sure. It would just be nice if the users were compensated for the exploitation and abuse they're subjected to.

The US solution does not make users whole and does not meaningfully change anything. The EU solution meaningfully changes the offending company's behavior. I would rather have significantly less breaches of my information than a check for $6 in the mail every couple months.

The EU solution provides incentive for the government to attack large businesses with lawsuits. That’s predatory and will lead to large businesses trying to lobby the EU to go after their competitors.

That just seems dysfunctional.

Re: Have I Been Pwned 2.0

#276
post #261
post #244

Earlier quoted context omitted.

All your examples are not things that commonly are job titles, so you are not "extending logic".

The things he mentioned are of the same class, so yes, it does "extend the logic". Just because the name for something is confusing, that doesn't change the nature of the thing named.

None of the things mentioned are common job titles, so no, they are not the same class.

Re: Have I Been Pwned 2.0

#277
post #22

He should partner with a law firm, for class action lawsuits, for every breach due to negligence (which is probably all of them). Tie in to a banking service, so you can do direct deposits to many millions of people, every time there's new settlements paid, and you'll be a folk hero. Get lawyers who want negligent companies to actually regret the breaches, with judgements that hurt. (Rather than a small settlement th…

Heh, such an American response. Sue everyone and everything, lawyers gets paid. But at the end of day, nothing changes. Meanwhile in EU, we have laws like NIS2, where if negligent in non-compliance. Fines are 10mil. EUR or 2% of global annual revenue. Eg.: If Apple gets $8bil. fine, yep that changes quite a lot I think. :)

Do either of these approaches actually solve the problem? I think companies won't take it seriously unless their executives do, and their executives won't unless they are personally punished in a way compensation can't compensate for. Cane them Singapore style.

Re: Have I Been Pwned 2.0

#278
post #22

He should partner with a law firm, for class action lawsuits, for every breach due to negligence (which is probably all of them). Tie in to a banking service, so you can do direct deposits to many millions of people, every time there's new settlements paid, and you'll be a folk hero. Get lawyers who want negligent companies to actually regret the breaches, with judgements that hurt. (Rather than a small settlement th…

Heh, such an American response. Sue everyone and everything, lawyers gets paid. But at the end of day, nothing changes. Meanwhile in EU, we have laws like NIS2, where if negligent in non-compliance. Fines are 10mil. EUR or 2% of global annual revenue. Eg.: If Apple gets $8bil. fine, yep that changes quite a lot I think. :)

It's with American companies in mind. Though I expressly addressed that it isn't about lawyers getting paid, and also how this might change things (motivate companies to behave responsibly, in this regard)

Basically, we have a high-corruption society, especially in 2025, but there's still vestiges of a system that can be leveraged in the public's interest, if you contort just so.

Re: Have I Been Pwned 2.0

#279

Too much scrolling. I prefer the old page.

They could preserve the same basic concept but scrunch it vertically a lot. Right now, the tiles in each column are spaced out so much that if you moved them all into one column, they wouldn't overlap.

Instead, they could stagger them. Some blank space would still make it easier to understand visually, just not as much. If they did this, it would be a bit harder to see how which date-circle on the timeline corresponds to which tile, but that could be fixed somehow, like a dotted line that joins a tile to its circle or by moving the circle to one side of the center line.

They could also shrink the contents of the tiles themselves.

(1) There's no reason to have MORE space after "Compromised data:" than before it. It wastes space, and (IMHO) aesthetically it looks very awkward and clumsy.

(2) Personally, I'd also not double-space the bullet items. I can see how it adds emphasis, but it wastes a lot of space and to me it looks bad.

(3) Too much vertical space above the "View Details" button. Sure, some padding is nice, but why so much more here than between the icon (at the top of the tile) and the first paragraph?

Re: Have I Been Pwned 2.0

#280

Earlier quoted context omitted.

If they design the road to make it harder to follow the rules it is bad.

Bad for the driver, good for the government. That's exactly the point.

Not really. If you hit a person with your car and that person becomes disabled. It will be way more expensive for the govt in the long run compared to a few fines.
Post reply on HN