Live data from Hacker News

Two billion email addresses were exposed

troyhunt.com

361–370 of 470 posts

Re: Two billion email addresses were exposed

#361

Earlier quoted context omitted.

> But the site does not give me any way to take action. It gives you as much information as you should be given. Any more information would just be spreading around the hacked dataset. It does give you an awful lot of information about the specific hacks that exposed your information, and what was the content of that exposure. You may have been owned, but the way you were owned doesn't really matter e.g. I don't care…

So it gives me the information that my email has been exposed. Where? In what service? Did my password got leaked too? I can't change password / delete the account if I don't know where. Did any other data got leaked? Anything sensitive? Do I have to cancel my credit card? Were any files leaked as well? My home location? At this point HIBP is next to useless. And how showing me WHAT is in the database about the email…

Btw they are not storing more info along the email address, because that would be way too risky. Just imagine the HIBP database being leaked.

Also, they don’t always know where your info has leaked. Some datasets are aggregates.

Re: Two billion email addresses were exposed

#362

Earlier quoted context omitted.

> there does not seem to be any way for _me_, the person affected, to know what password were breached You should be using a unique randomly-generated password for each website. That way, one breach doesn't lead to multiple accounts getting hijacked AND you'll know which passwords were breached solely based on the website list. The only passwords I still keep in my head are: 1. The password to my password manager 2.…

Nice. Now I'd like to know WHICH password got leaked. That way the breach impact can quickly be limited. Troy probably would share that information for a price. Not sure whom to pay though - the "good" guy who won't say a word, or a criminal who will happily share it with me? It's possible the latter would be cheaper too.

They don’t store email addresses with password in the database. That would be way too risky. These are separate databases, so you can lookup your email address, and separately check a password.

Re: Two billion email addresses were exposed

#363
post #53

Earlier quoted context omitted.

https://haveibeenpwned.com/Passwords

my password: 2,408 password: 46,628,605 your password: 609 good password: 22 long password: 2 secure password: 317 safe password: 29 bad password: 86 this password sucks: 1 i hate this website: 16 username: 83,569 my username: 4 your username: 1 let me login: 0 admin: 41,072,830 abcdef: 873,564 abcdef1: 147,103 abcdef!: 4,109 abcdef1!: 1,401 123456: 179,863,340 hunter2: 50,474 correct horse battery staple: 384 Correc…

Spaces are skewing the numbers lower. Remove them from any of those and see the number increase at least an order of magnitude. That “let me login” goes from 0 to 4,714 just by removing spaces (“letmelogin”).

Re: Two billion email addresses were exposed

#364
post #36
post #31

There have been enough data breaches at this point that I'm sure all my info has been exposed multiple times (addresses, SSN, telephone number, email, etc). My email is in over a dozen breaches listed on the been pwned site. I've gotten legal letters about breaches from colleges I applied to, job boards I used, and other places that definitely have a good amount of my past personal information. And that's not even co…

Addresses? Most of the time addresses are a matter of public record. I have used https://www.fastpeoplesearch.com/ a couple of times to search for people's addresses and it really works. One day a close friend excitedly told me she bought a new house and I told her the address before she told me about it. Telephone number? There used to be phone books. And I still instinctively think they should be public.

I was thinking the same thing. Can you imagine the headline?

"Forget Hackers! Phone Company Delivers Your Private Info—Including Your Home Address—Directly to Strangers!"

Re: Two billion email addresses were exposed

#365

Earlier quoted context omitted.

(the keyboard smash username is apropos) > Per-account alias might sound much Not only does this not sound too much, this is a feature Apple offers called Hide My Email: https://support.apple.com/en-us/102548

And one day you've had it with Apple's latest user-hostile shenanigans and switch to Linux. What now? Do you just keep paying for iCloud+ forever?

In my experience the overwhelming majority of services permit me to change my email address.

Re: Two billion email addresses were exposed

#366
post #36
post #31

There have been enough data breaches at this point that I'm sure all my info has been exposed multiple times (addresses, SSN, telephone number, email, etc). My email is in over a dozen breaches listed on the been pwned site. I've gotten legal letters about breaches from colleges I applied to, job boards I used, and other places that definitely have a good amount of my past personal information. And that's not even co…

Addresses? Most of the time addresses are a matter of public record. I have used https://www.fastpeoplesearch.com/ a couple of times to search for people's addresses and it really works. One day a close friend excitedly told me she bought a new house and I told her the address before she told me about it. Telephone number? There used to be phone books. And I still instinctively think they should be public.

> Telephone number? There used to be phone books. And I still instinctively think they should be public.

I used to think the same. Around here I feel until a few years ago most people I knew with secret phones were people I would prefer to have fewer interactions with: people who frequently got into trouble, tried to scam others etc.

These days I’m more in the camp of layered security. Whatever I can do to make it harder for an attacker, the better.

> I have used https://www.fastpeoplesearch.com/ a couple of times to search for people's addresses and it really works.

Tangential:

Sorry, you have been blocked You are unable to access fastpeoplesearch.com

(Safari on a stock iPhone, mobile broadband from the biggest and most well known telecom company in my country, ipv6 address.)

Re: Two billion email addresses were exposed

#367
post #362

Earlier quoted context omitted.

Nice. Now I'd like to know WHICH password got leaked. That way the breach impact can quickly be limited. Troy probably would share that information for a price. Not sure whom to pay though - the "good" guy who won't say a word, or a criminal who will happily share it with me? It's possible the latter would be cheaper too.

They don’t store email addresses with password in the database. That would be way too risky. These are separate databases, so you can lookup your email address, and separately check a password.

[deleted]

Re: Two billion email addresses were exposed

#368

Earlier quoted context omitted.

That's the default in this day and age, no?

I mean, probably should be. But for me, no. Well, not my personal computer anyway. That's a mistake, I know. But corporate computer yes. So no, I don't think "in this day and age" necessarily. And I believe that the vast majority of "normal" users don't do full drive encryption either. But yes, we should.

Last I looked, windows and Mac installs both push the user to set up bitlocker or FileVault, respectively. You have to actively say no if you don’t want it.

Re: Two billion email addresses were exposed

#369

Earlier quoted context omitted.

I used per-account email with alias services and password managers. Also started migrating old accounts in free time. Now its pretty easy to tell the source of leak by email addresses as well as sources of spam. --- Per-account alias might sound much, but using sieve filtering [1] is amazing, and you can get a comprehensive filtering solution going with 'envelope to' (the actual address receiving the email) + 'header…

I just use + @gmail.com At the end of day day it’s all delivered to myname@gmail.com mailbox, but I can use filters based on part after “+”.

The downside is that https://haveibeenpwned.com/ can only find "exact email" addressed, as in, you must search for myname@gmail.com, myname+service1@gmail.com, etc.

Re: Two billion email addresses were exposed

#370

Earlier quoted context omitted.

And one day you've had it with Apple's latest user-hostile shenanigans and switch to Linux. What now? Do you just keep paying for iCloud+ forever?

In my experience the overwhelming majority of services permit me to change my email address.

Of course. But I have hundreds of user accounts, as probably many people do. I would not enjoy changing all those email addresses.
Post reply on HN