Live data from Hacker News

DarkBeam leaks billions of email and password combinations

securityaffairs.com

31–39 of 39 posts

Re: DarkBeam leaks billions of email and password combinations

#31
post #18

Earlier quoted context omitted.

Services already exist that does this. Some password managers will check but the popular service often talked about on here is https://haveibeenpwned.com/

Thank you, I've edited my comment to be more specified

They used to publish a torrent with hashes, but then went full SaaS.

Re: DarkBeam leaks billions of email and password combinations

#32

Each time a breach like this happens I want to download the file and check if 1. My emails are in the dataset, and 2. Any of my passwords are in that dataset. I really just want the collection of passwords so that I can use it as a check against any of my current passwords. [EDIT: I know about haveibeenpwned.com; I'm not asking for a service that I send a http request to to determine if a single username exists in th…

HIBP lets you download their hashed passwords DB to check against.

https://github.com/HaveIBeenPwned/PwnedPasswordsDownloader

Re: DarkBeam leaks billions of email and password combinations

#33

Each time a breach like this happens I want to download the file and check if 1. My emails are in the dataset, and 2. Any of my passwords are in that dataset. I really just want the collection of passwords so that I can use it as a check against any of my current passwords. [EDIT: I know about haveibeenpwned.com; I'm not asking for a service that I send a http request to to determine if a single username exists in th…

I agree - download all the passwords and don't single out what you're checking for someone else to see.

I don't know why we can't use this kind of thing for better privacy everywhere.

A similar example (outside the realm of passwords) would be when checking for a software update. Instead of sending "i have software xyz version 1.2.3", just download a current list of software and check it locally against your software. Probably would be faster anyway to download a static dataset instead of hitting a remote database.

Re: DarkBeam leaks billions of email and password combinations

#35

Each time a breach like this happens I want to download the file and check if 1. My emails are in the dataset, and 2. Any of my passwords are in that dataset. I really just want the collection of passwords so that I can use it as a check against any of my current passwords. [EDIT: I know about haveibeenpwned.com; I'm not asking for a service that I send a http request to to determine if a single username exists in th…

Each time a breach like this happens I want to download the file and check if;

1. People on my s*t list are in the dataset, and

2. Any of their passwords are in that dataset.

Then I can use the information to make their lives miserable.

Re: DarkBeam leaks billions of email and password combinations

#36
post #18

Earlier quoted context omitted.

Services already exist that does this. Some password managers will check but the popular service often talked about on here is https://haveibeenpwned.com/

Thank you, I've edited my comment to be more specified

Download Have I Been Pwnds dataset then: https://github.com/HaveIBeenPwned/PwnedPasswordsDownloader

Re: DarkBeam leaks billions of email and password combinations

#37

Each time a breach like this happens I want to download the file and check if 1. My emails are in the dataset, and 2. Any of my passwords are in that dataset. I really just want the collection of passwords so that I can use it as a check against any of my current passwords. [EDIT: I know about haveibeenpwned.com; I'm not asking for a service that I send a http request to to determine if a single username exists in th…

If you use any of the better password managers this feature exists and runs automatically. If you don't want to go that route, then you can make use of https://haveibeenpwned.com/

I have a gmail account which google one shows, it along with a username has been leaked on dark web, but haveibeenpwned shows email was not found in any data breach. How is that possible?

Re: DarkBeam leaks billions of email and password combinations

#38

Earlier quoted context omitted.

If you use any of the better password managers this feature exists and runs automatically. If you don't want to go that route, then you can make use of https://haveibeenpwned.com/

I have a gmail account which google one shows, it along with a username has been leaked on dark web, but haveibeenpwned shows email was not found in any data breach. How is that possible?

They're using different data sources.

Re: DarkBeam leaks billions of email and password combinations

#39

No evidence is presented that anybody but the security researcher noticed the unprotected data. The data is a compilation of previously leaked emails.

"exposing records with user emails and passwords from previously reported and non-reported data breaches." I think you mean to say that there is no evidence presented precluding someone grabbing the data?

Not sure what your point is about non-reported, but that's still previously leaked data. It probably means stuff found in the dark webs.
Post reply on HN