Live data from Hacker News

1k Data Breaches Later, the Disclosure Lag Is Worse

troyhunt.com

41–50 of 133 posts

Re: 1k Data Breaches Later, the Disclosure Lag Is Worse

#41
post #19

For years, I've been trying my best to stay low-key when it comes to my personal information on the internet. I don't create new accounts, I never cross-login with my email address, I don't use phones. Certainly not perfect, but a lot of times I'm preferring privacy over convenience. At the same time, my government and society at large is pushing more and more for "digital everything". It's great when it works. But t…

>We need to establish measures of accountability for data holders

This is true, and it needs to change. The incentives are warped right now, as a decent chunk of global GDP traces itself back to ad tech.

Re: 1k Data Breaches Later, the Disclosure Lag Is Worse

#42

I have a custom domain for my emails with catch all. When I create an account somewhere I just use @my-domain.com Can I find out if any of my emails are in leaks with a service somewhere?

That's literally what Have I Been Pwned is for.

https://haveibeenpwned.com/

Re: 1k Data Breaches Later, the Disclosure Lag Is Worse

#43
post #42

I have a custom domain for my emails with catch all. When I create an account somewhere I just use @my-domain.com Can I find out if any of my emails are in leaks with a service somewhere?

That's literally what Have I Been Pwned is for. https://haveibeenpwned.com/

One by one, but I think the question is about the entire domain name

Re: 1k Data Breaches Later, the Disclosure Lag Is Worse

#44
post #6

Earlier quoted context omitted.

This is a bad idea, for multiple reasons. https://www.troyhunt.com/here-are-all-the-reasons-i-dont-mak...

>Most breaches already contain hashed passwords It could show the hash instead. >No, it's not ok that these passwords are already out there So it's better that people have to pay for it instead of getting this information for free? >Because it's important to say "I don't store passwords in HIBP" This is a personal choice. >I'm not your personal lookup service The idea is that this would be done by the site itself and…

Hashes can be cracked, and end users won't understand how to create password hashes to check which one was leaked. Plus, salts exist.

Passwords shouldn't matter anyways. Use a password manager and be done with it. The real issue is metadata which can't easily be changed - phone numbers, addresses, and the like. If any of that data is leaked, it becomes much harder to contain impact. You can't move addresses every time your address gets leaked online.

Re: 1k Data Breaches Later, the Disclosure Lag Is Worse

#45

>why is it still needed? It's not needed. There are already alternatives that could take its place. Some of them are able to actually show you what data leaked instead of leaving you blind of what was actually included in the breach.

Can you give examples of these alternatives?

I use Snusbase (https://snusbase.com). They've been around since around 2016 and haven't had any issues legally - they're the longest-standing data breach search engine besides HIBP, as far as I know.

(This is not an advertisement.)

Re: 1k Data Breaches Later, the Disclosure Lag Is Worse

#46
post #42

Earlier quoted context omitted.

That's literally what Have I Been Pwned is for. https://haveibeenpwned.com/

One by one, but I think the question is about the entire domain name

You can have haveibeenpwned.com check for the custom domain itself. For instance, I get notified if any email of our family domain get leaked (not just mine).

Re: 1k Data Breaches Later, the Disclosure Lag Is Worse

#47
post #29

Earlier quoted context omitted.

> . I don't create new accounts, I never cross-login with my email address I honestly tend to think this is the only viable long term strategy. Let's face it: In a truly global internet where every single forum or website is hosted in a different country with a different jurisdiction, hoping that every single actor will act responsibly is just delusional. It is not what we see. It is not happening and it is not going…

Is the alternative just accepting that my data is out there? Even if I never used any online service, there are databases out there with my information anyway. Just figure anything online that you aren't securing yourself is compromised. Minimize the effect that has on your life. Identify theft is annoying, but it rarely has severe effects. You will have to go out of your way to be truly anonymous online, and it migh…

> Otherwise, just assume everything you do online is public and act accordingly.

This is such a depressing reality. It's also what governments want you to believe. If you aren't able to speak your mind about anything anonymously, then you won't be able to, say, spread ideas that go against them.

Admitting defeat at all and not even trying to teach people about privacy results in the "I don't care, what's the point?" attitude that plagues many people today.

Re: 1k Data Breaches Later, the Disclosure Lag Is Worse

#48
post #11

Earlier quoted context omitted.

Depends where they are in the world. I _think_ GDPR would be a good enough business reason, as they set a ticking clock of 72 hours from the breach to notifying individuals who are in the breach. And the fines involved are pretty steep (almost effing vertical for some).

A minor problem with GDPR is enforcement. At least in germany it feels like you need a very dedicated and persistent person to make the case against a company/service (bonus points if they get media attention). Other countries are a bit better but it generally is not very consistent. The enforcement for most small to mid-sized companies is often just not present and resources for relevant agencies are often only relu…

At least there is the very dedicated and persistent https://noyb.eu :)

Re: 1k Data Breaches Later, the Disclosure Lag Is Worse

#49
post #34
post #31

These days I treat other people's data like it's a live hand grenade. Case in point (bit of a shameless plug here :) I'm working on an App called Hockeytastic. It's an ice-hockey stickhandling app that my son's been using for months: the engine is solid but it looked like shit. However, his coach told me to get it on the app stores and sell subs. That meant I needed to clean it up, build a DB, store stuff etc. Anyway…

I wish that were the case, but because of there being barely any consequences for breaches, it's much more profitable to store everything you can and sell it to the highest bidder. Make it a huge risk to store data, then companies will start treating data like a live hand grenade.

That's exactly what the GDPR tried. If only it was properly enforced

Re: 1k Data Breaches Later, the Disclosure Lag Is Worse

#50
post #42

Earlier quoted context omitted.

That's literally what Have I Been Pwned is for. https://haveibeenpwned.com/

One by one, but I think the question is about the entire domain name

If you sign in that's an option on your dashboard. You need an account because you need to verify the domain is yours
Post reply on HN