Live data from Hacker News

Pwned or Bot

troyhunt.com

41–50 of 89 posts

Re: Pwned or Bot

#41

I pay for my email that gives me a lot of aliases and most of them have not been pwned yet. So with his tool I would be flagged as a bot. Honestly, doesn't sound like a great idea to be frank. There must be large swaths of people that have either been careful or have specific emails that they use for certain purposes that haven't been pwned. The question, what should happen if I haven't been pwned? Should I not be ab…

It's not his idea, he's saying that there are people out there who are already (mis)using the data for this.

Sort of. He does encourage this use-case in the final paragraph.

> Applying "Pwned or Bot" to your own risk assessment is dead simple with the HIBP API and hopefully, this approach will help more people do precisely what HIBP is there for in the first place: to help "do good things after bad things happen".

Re: Pwned or Bot

#42

Wouldn't bad actors just push their fake email addressess to haveibeenpwned in fake leaks? Steps: 1- periodically set up a legitimate looking service, possibly proxying real services. 2- wait a year or two for your fake service to premiate throughout the www and for seach engines to index it. 3. Mix your bot email addresses with legitimate previously pwned addresses. 4- proclame "woe is me, for thyself hasth been pwn…

It is going to happen, and some people will make money off it by farming such addresses, but it raises the time and the cost to obtain a plausible email address for fraud.

Re: Pwned or Bot

#43
post #25

Earlier quoted context omitted.

Edit: I misunderstood Troy. Original comment: No, it doesn't penalize them (at least not his idea, implementations might), it simply fast tracks pwned emails and doesn't apply the normal bot checks that would otherwise apply to everyone.

I wonder how many pwned email and password pair still match. Crooks can take control of these pwned accounts and pretend to be trustworthy.

It depends on the risk. I have an account that was pwnd (with the same password) but there is no risk to me as there isn't anything useful in that account (not even a DoB, Address or even a Name.) Worse case, someone changes the password and locks me out. Then I'll create another account as it's not a big deal.

Re: Pwned or Bot

#45
post #26

I'll be a contrarian: I like it. Is it a black and white silver bullet one call destroys 'em all solution? Not even close. But, like he states in his article; from a "defence in depth" its another strong signal. Are you a bad guy just because you have a weirdo email (which I do)? No. Are you a bad guy just because you use tor? No. Are you a bad guy just because you're trying to make a purchase during an extreme surge…

> you're going to jump through a lot more hoops than someone with an ancient email and a residential ip address.

I understand this kind of reasoning.

At the same time I see a potential to snowball. This will encourage people to move away from weird addresses. Which will make it an even more effective filter and will justify stricter measures. So more people will move away. Etc.

Re: Pwned or Bot

#47

Facebook and Twitter are basically closed to new users. If you've gone this far without an account, your new one will be shut down for being a bot within hours of creating a new account, or flagged for "extra verification" which requires sending a government ID to these companies so they can verify that you didn't photoshop a fake government ID. This new approach seeks to extend this feature to the entire internet .…

I created a Facebook account a few months ago to use Marketplace. The profile has only a name and unique-to-facebook email. I always use it in Firefox Containers.

Still active, and I've sold a handful of things with it.

Re: Pwned or Bot

#48
post #3

This is a cute "hack" for bot detection, but it's too unpredictable for the real world. Far too many users with good security hygiene are penalized by this system Plus, this might incentivize hackers to defeat the system by logging into and using email accounts pwned in these breaches.

> Plus, this might incentivize hackers to defeat the system by logging into and using email accounts pwned in these breaches. This already happens at a large scale anyway. There's hundreds, if not thousands of "account shops" and sellers online selling hacked accounts for all sorts of services. Everything from Spotify to Twitter to news sites. They ingest new breaches (or use automated tools to go hack sites and dump…

I actually thought this was going to be the topic based on the title: distinguishing between entirely fake accounts, and pwned real accounts.

Re: Pwned or Bot

#50

Wouldn't bad actors just push their fake email addressess to haveibeenpwned in fake leaks? Steps: 1- periodically set up a legitimate looking service, possibly proxying real services. 2- wait a year or two for your fake service to premiate throughout the www and for seach engines to index it. 3. Mix your bot email addresses with legitimate previously pwned addresses. 4- proclame "woe is me, for thyself hasth been pwn…

At that point you'd be better off making those emails and signing up to a bunch of services. Bot emails aren't fresh for 2 years, and if they are somebody isn't doing their job properly.
Post reply on HN