Live data from Hacker News

Have I Been Pwned 2.0

troyhunt.com

301–310 of 323 posts

Re: Have I Been Pwned 2.0

#301

Earlier quoted context omitted.

How exactly is that supposed to prevent your data from getting stolen in a database leak?

This thread isn't about data in general, only passwords. So first of all, a strong password is much harder to crack in the instance that it's stored in a hashed form in the database. In the instance it's stored (unforgivably) in cleartext, it cannot be used, because an additional factor is required to authenticate. That is how exactly.

HIBP tracks full data breaches, not just password leaks. Screenshot from the article https://www.troyhunt.com/content/images/2025/05/image-19.png

If your physical address gets leaked having a unique random password doesn't help with that. It's still a good idea though.

Re: Have I Been Pwned 2.0

#302

Amazing that even within the last decade a site as large as LinkedIn could be storing unsalted passwords. How does anyone fail at this in the modern era?

IIRC linkedin was one of the breaches where I got a spam email to my linkedin address, told them and they were like "can't be us - must be you who has been hacked". And then later "ah yeah was us, but no personal data was stolen". Like email address is not personal - lucky me for having a catch all domain and being able to just block the address I had used with linkedin.

Re: Have I Been Pwned 2.0

#303
post #31

Who has the record for being in the most breaches? My main email seems to currently be in 40 breaches, earliest one in from June 2011 (HackForums, don't even remember what that is), and last one in September 2024 (FrenchCitizens, although I'm not French nor have I ever lived in France).

steve@apple.com has 82 breaches. Good that he gave it to his CEO decades ago.

Re: Have I Been Pwned 2.0

#304
post #297

Earlier quoted context omitted.

They are not of the same class. The class is "job title", implying employment. "Regional director" is a job title. The others are not.

"Microsoft Regional Director" is not a job title. It is an award that Microsoft gives out only to non-employees. You might think the award has a confusing name, and you would be correct. What you cannot be correct in asserting is that an award makes someone an employee because that award has a confusing name. That isn't a question of "semantics", if you assert that award makes him an employee, you are simply wrong.

I'll repeat what I said in a related thread: I'm not saying it makes him an employee. I'm saying those are bad attempts to argue the title isn't confusing.

Re: Have I Been Pwned 2.0

#306
post #108

Earlier quoted context omitted.

I think this would have a negative effect. Getting a company to publicly announce a breach is hard today. Your suggestion would make it even harder, and more data breaches would be kept from the public because of the consequences. I would rather know that a company messed up and change my password, than not knowing

> I think this would have a negative effect. How? Disclosure should already be legally required--class-actions and lawsuits should already be a thing. The Have I Been Pwned data sets aren't volunteered by these companies. It's a catalog of leaked data. The class-action response of "identity monitoring" is nonsense. More companies, if they can't afford to or don't want secure data, shouldn't collect it or should aggre…

Amen. User data should be a liability. The incentive should be avoiding data collection.

Re: Have I Been Pwned 2.0

#307
post #220

Like many people I have a "main" email address, and I use per-company addresses for almost everything else. Now that the domain-searches require subscriptions this site has become much less useful. I just added my domain to the site again and I see "2,243 Total Breached Addresses", and "18 Addresses excluding Spam Lists", but I have no idea what they are. Attempting to click the links shows me I need to "upgrade" to…

I used to just add the +something in my email but now I try and remain diligent to create a masked email. When I first started, I foolishly did it with my domain name but have since moved to creating it with @fastmail.com.

Why do you feel it’s foolish that you used your own domain name?

Re: Have I Been Pwned 2.0

#308

Earlier quoted context omitted.

"Microsoft Regional Director" We can debate semantics but if you describe yourself with a job title attached to a company then I suggest that you have an association which looks rather like ... employment.

Its not semantics at all, you just are excusing your own misunderstanding. He didn't describe himself with a job title, and he even explicitly states directly after listing those awards, that he is not an employee of Microsoft. Extending your logic, I have a CCIE, so if I ever state I'm a CCIE, I'm an employee of Cisco? I have a masters degree by coursework from a university, so I I ever state I have an Msc, I'm an e…

Well TBH, if you say that you are a cisco security engineer, I would assume you are from Cisco. Same for ACME whatever.

He made it clear that he is not MS but this is the only time I saw such a misleading "title"

Re: Have I Been Pwned 2.0

#309
post #220

Earlier quoted context omitted.

I used to just add the +something in my email but now I try and remain diligent to create a masked email. When I first started, I foolishly did it with my domain name but have since moved to creating it with @fastmail.com.

Why do you feel it’s foolish that you used your own domain name?

I think OP means that they used aaa+facebook@smthg.com, so aaa@smthg.com is now revealed to be their main address.

As opposed of having facebook@smthg.com only

Re: Have I Been Pwned 2.0

#310
post #220

Earlier quoted context omitted.

I used to just add the +something in my email but now I try and remain diligent to create a masked email. When I first started, I foolishly did it with my domain name but have since moved to creating it with @fastmail.com.

Why do you feel it’s foolish that you used your own domain name?

Because it has my name in the domain. Since I was doing it for to help with privacy too, it seemed counterintuitive.
Post reply on HN