Live data from Hacker News

We are discontinuing the dark web report

support.google.com

31–40 of 61 posts

Re: We are discontinuing the dark web report

#31
post #11

I found the info not actionable because it wouldn’t say what actual values were posted. I have a common name Gmail account. The password is rather complex and I would be surprised if it leaks as only I and Google know it. However, I would get reports that it’s on the dark web with blanked out password values. So I never knew if they actually compromised or just something else. They would also report when some random…

I never got the Google dark web reports, but my credit card used to send me reports constantly saying that my email address was 'found on the darkweb.' Okay, that's not useful information. If it showed me if there were associated passwords, that might be helpful, but just saying my address was found on the darkweb is meaningless. My email address is public information. The worst part is, it was an email address I had…

Well you could change the email address you use for the financial services only, and keep it secret. Then it would be harder to impersonate you.

Re: We are discontinuing the dark web report

#34
post #31

Earlier quoted context omitted.

I never got the Google dark web reports, but my credit card used to send me reports constantly saying that my email address was 'found on the darkweb.' Okay, that's not useful information. If it showed me if there were associated passwords, that might be helpful, but just saying my address was found on the darkweb is meaningless. My email address is public information. The worst part is, it was an email address I had…

Well you could change the email address you use for the financial services only, and keep it secret. Then it would be harder to impersonate you.

Or, use a service that lets you generate an address for each business you deal with or use case you have so you can treat them as disposable. After chasing down spammers and companies selling my info, including my email, I found this was easier to keep up with and is more effective. Spam me once or sell it to another company, and I burn that address, replacing it with the original company if I really need them to keep in contact.

Re: We are discontinuing the dark web report

#35
post #7

> While the report offered general information, feedback showed that it didn't provide helpful next steps. Translation: We don’t actually want to keep spending time, money, and resources on this.

No, not really. The way this worked is that if they detected personal information on a "dark web" (per their definition -- I have no idea what this actually meant) site, they would show you a report that told you which PII was listed, and it was usually things like your fname/lname, address, phone or location. The problem is that it wasn't actionable [because it was the dark web], unlike their current personal data privacy features and data removal tool.

This is one where I don't blame them for killing it because "it" wasn't really even a product -- it was just a very basic, not useful at all, report.

Re: We are discontinuing the dark web report

#37
post #31

Earlier quoted context omitted.

Well you could change the email address you use for the financial services only, and keep it secret. Then it would be harder to impersonate you.

Or, use a service that lets you generate an address for each business you deal with or use case you have so you can treat them as disposable. After chasing down spammers and companies selling my info, including my email, I found this was easier to keep up with and is more effective. Spam me once or sell it to another company, and I burn that address, replacing it with the original company if I really need them to kee…

I tried to do that but found out there's almost no services that I would want to treat my account there disposable. If I bother to provide them my email address -- I usually also want to access my account there later (e.g check order status).

There are tens of services where I'd like it disposable, but hundreds of services where account is warranted. And some of those thousands will be compromised some day.

Re: We are discontinuing the dark web report

#38
Google discontinuing this is unfortunate timing given the recent breach surge (700Credit, SoundCloud, LinkedIn leak).

Alternatives: haveibeenpwned.com (free), 1Password Watchtower, Bitwarden breach reports.

The harder part isn't knowing about breaches—it's actually rotating passwords afterward. Most people know they should but don't because it's tedious.

Automated rotation tools are emerging but need careful security architecture (local-only, zero-knowledge) to avoid creating new attack vectors.

Re: We are discontinuing the dark web report

#39

I might be misremembering this but FWICR on Chrome it would link your saved passwords with the dark web report, and automatically recommend you change any account that had the same password as the "pwned" account found in the dark net. Was pretty useful.

Apple has this feature on iOS. no idea where they source the info from, but in your keychain it will say something like "this password has appeared in a data leak"

Re: We are discontinuing the dark web report

#40
post #11

I found the info not actionable because it wouldn’t say what actual values were posted. I have a common name Gmail account. The password is rather complex and I would be surprised if it leaks as only I and Google know it. However, I would get reports that it’s on the dark web with blanked out password values. So I never knew if they actually compromised or just something else. They would also report when some random…

Yeah.. I have a five letter email that's a common first and last name @ gmail.com. I second everything you said. Getting report hits every few days are useless given how few sites do any kind of validation. :-/
Post reply on HN