Live data from Hacker News

Firefox Monitor

monitor.firefox.com

41–50 of 227 posts

Re: Firefox Monitor

#42
post #32
post #2

How does this relate to HaveIBeenPwned.com? Is it a separate effort? Does it have more data? Is it built on top of their data? I've seen other services (like 1Password) just rely on HaveIBeenPwned because it's pretty solid – seems like it would be nice for the industry to coalesce around it and build these kinds of alerting features on top of it.

I find spycloud a lot more useful as website tbh. They at least tell you explicitly which passwords were leaked.

How does the password matter though? Won’t it usually be some hashes anyway and if you are breached you should just change your password anyway.

Re: Firefox Monitor

#44
This is basically a frontend for haveibeenpwned. Creating it costed Mozilla money. Why did they do this instead of linking directly to the original page?

Re: Firefox Monitor

#45

Does this have an API? I would pay a nominal amount to have this tied to my 1password DB to crosscheck all the emails I use. Since I use a different email for each site, I'd like this automated. Also do you think this is the same value as LifeLock?

1password already is integrated with Have I Been Pwned, which sounds like the same dataset that this is using. I believe it's exposed via Watchtower in the app. (https://1password.com/haveibeenpwned/)

Re: Firefox Monitor

#46
post #44

This is basically a frontend for haveibeenpwned. Creating it costed Mozilla money. Why did they do this instead of linking directly to the original page?

Because the Mozilla brand is more trusted than a random website with ‘Pwned’ in its name. Also, it's being built into Firefox so having a website for it too seems like a good idea.

Re: Firefox Monitor

#48

Disclaimer: Firefox Monitor dev here. Note: We just released a "V2" of the site that allows you to add multiple email addresses to monitor, and (then) to have all your breach alerts sent to your single primary email address.

Nice work! Small suggestion -- it would be nice to be able to to have the notification sent to the breached email and the primary email

Re: Firefox Monitor

#49
post #39

My email appears in six breaches. Only one of the companies I recognize. I have never done business with the other five. This pisses me off. Not that the data was stolen -- these things happen. It pisses me off that my data was shared with third parties without my knowledge or consent. And no, a paragraph buried in the basement of a privacy policy does not constitute informed consent. This system would be more useful…

So, I 100% agree with you and think a sentence in multi-page privacy policy is not informed consent.

Recently in EU GDPR regulation brought in some strict measures on how consent is requested and how data is shared and managed, I was delighted when websites started sending me emails asking me for content to market and share data.

However I am now seeing a bunch of websites doing the shady tactic of showing a full page pop-up on mobile site with all 30+ checkboxes pre-ticked allowing them full access of my data. Fuck such sites.

Re: Firefox Monitor

#50
If it's using the haveibeenpwned service then why does it say my email has been found in less number of data breaches compared to the number on the haveibeenpwned site (11 vs 14)?
Post reply on HN