Live data from Hacker News

Firefox Monitor

monitor.firefox.com

31–40 of 227 posts

Re: Firefox Monitor

#32
post #2

How does this relate to HaveIBeenPwned.com? Is it a separate effort? Does it have more data? Is it built on top of their data? I've seen other services (like 1Password) just rely on HaveIBeenPwned because it's pretty solid – seems like it would be nice for the industry to coalesce around it and build these kinds of alerting features on top of it.

I find spycloud a lot more useful as website tbh. They at least tell you explicitly which passwords were leaked.

Re: Firefox Monitor

#33
Does this have an API? I would pay a nominal amount to have this tied to my 1password DB to crosscheck all the emails I use. Since I use a different email for each site, I'd like this automated.

Also do you think this is the same value as LifeLock?

Re: Firefox Monitor

#34
would be a lot more helpful if it clarified if it's hashed passwords or plaintext, also if they were hashed with a site-wide salt or per-user salt.

imo, this distinction is too important to be omitted from a short summary.

Re: Firefox Monitor

#35

I checked my email address and it says my data was lost by verifications.io. I've never heard of that site before and going there didn't reveal any clues. I googled the name and found a report [1] on the breach. They lost control of records on 2 billion email addresses. [1]: https://www.forbes.com/sites/daveywinder/2019/03/10/2-billio...

I had similar with a website called Apollo. Story linked below[1].

Edit: Their opt out page and main site[2]. Notably, Firefox Developer Edition warned me and linked me to the main Firefox Monitor page, so it's something that's being built into Firefox.

[1] https://www.wired.com/story/apollo-breach-linkedin-salesforc...

[2] https://www.apollo.io/privacy-policy/

Re: Firefox Monitor

#36
Disclaimer: Firefox Monitor dev here.

Note: We just released a "V2" of the site that allows you to add multiple email addresses to monitor, and (then) to have all your breach alerts sent to your single primary email address.

Re: Firefox Monitor

#37

I really wish Firefox would focus, and I don't mean Firefox Focus. If they focused on making it simple, fast, and reliable, it would have a much better shot at taking market share from Chrome. On top of that, I wish everything on top of a browser was truly optional - that they didn't have reminders of sync spread throughout the app, and that they didn't have a Pocket button in the toolbar unless I logged in with Pock…

Perhaps this is their focus. Not FF monitor, but privacy. Going up against/with Apple as a privacy-conscious alternative to Chrome etc. From that viewpoint, this is in line with that.

Re: Firefox Monitor

#38

Does this have an API? I would pay a nominal amount to have this tied to my 1password DB to crosscheck all the emails I use. Since I use a different email for each site, I'd like this automated. Also do you think this is the same value as LifeLock?

https://haveibeenpwned.com/API/

https://1password.com/haveibeenpwned/

Re: Firefox Monitor

#39
My email appears in six breaches. Only one of the companies I recognize. I have never done business with the other five.

This pisses me off. Not that the data was stolen -- these things happen. It pisses me off that my data was shared with third parties without my knowledge or consent. And no, a paragraph buried in the basement of a privacy policy does not constitute informed consent.

This system would be more useful if it could report how these companies got my data. I want to know who betrayed me.

It wouldn't be a terrible thing to have privacy legislation that forces companies that sell your data to disclose what information they sold, when, and to whom.

Re: Firefox Monitor

#40

Does this have an API? I would pay a nominal amount to have this tied to my 1password DB to crosscheck all the emails I use. Since I use a different email for each site, I'd like this automated. Also do you think this is the same value as LifeLock?

The footer of the results list says “Breach data provided by Have I Been Pwned” and it looks like Have I Been Pwned has an API here https://haveibeenpwned.com/API/v2.

I personally don’t see a benefit to Firefox Monitor, aside from a new channel of exposure and branding for Firefox, if they are providing the same data Have I Been Pwned is.

Post reply on HN