Live data from Hacker News

Two billion email addresses were exposed

troyhunt.com

461–470 of 470 posts

Re: Two billion email addresses were exposed

#461

Earlier quoted context omitted.

It's quite certainly a up selling attempt. I once spend a couple of hours to see what was actually exposed in the infostealer breach my email appeared (eg: payment data? Physical address? Government id ?) to no avail. This service is toxic tbh.

The API is free. https://haveibeenpwned.com/API/v3

Respectfully, in context of my claim (that this is upselling attempt), your answer is untrue.

"You need an active subscription in order to provision an API key".

This is minimum $4.50 pm. Of course it's not a lot but let's not move the goalposts by discussing whether it's a fair price or not.

I don't want to say it's a lie, because I assume you didn't know.

API is a paid service, not free.

Separately, if I open the dashboard link while being logged out, the Web page promises:

"viewing stealer log entries that captured your email address"

Needless to say, this is also false (maybe true with a paid subscription?). If I click on the Stealer Logs in the dashboard it only shows "discord.com" (old account I used with this email was deleted years ago), and nothing else. Even though Breaches suggests there's something else.

This is not "logs" by any stretch of imagination.

Re: Two billion email addresses were exposed

#462
post #363

Earlier quoted context omitted.

my password: 2,408 password: 46,628,605 your password: 609 good password: 22 long password: 2 secure password: 317 safe password: 29 bad password: 86 this password sucks: 1 i hate this website: 16 username: 83,569 my username: 4 your username: 1 let me login: 0 admin: 41,072,830 abcdef: 873,564 abcdef1: 147,103 abcdef!: 4,109 abcdef1!: 1,401 123456: 179,863,340 hunter2: 50,474 correct horse battery staple: 384 Correc…

Spaces are skewing the numbers lower. Remove them from any of those and see the number increase at least an order of magnitude. That “let me login” goes from 0 to 4,714 just by removing spaces (“letmelogin”).

I guess this means passwords with spaces are safer!

Re: Two billion email addresses were exposed

#463
post #458

Earlier quoted context omitted.

How is it possible to have compromised password but not compromised the second factor? I don't understand the theory of leaking not enough factors. What is stopping webmasters from using 100FA?

> How is it possible to have compromised password but not compromised the second factor? Server-side (assuming weak password storage or weak in-transit encryption) or phishing (more advanced phishers may get the codes too but only single instance of the code, not the base key). > What is stopping webmasters from using 100FA? The users would hunt them down and beat them mercilessly?

So 2FA is a protection against the server's admin? Not even the user's protection but the webmaster's one?

Re: Two billion email addresses were exposed

#464

Earlier quoted context omitted.

Everyone has their own risk profiles, mine assumes I retain control over my domains and emails. I prepay for them several months in advance to make sure I don't lose ownership. any service provider worth their salt will have a human factor for customer support who can help you if any such issues show up.

Thank you for expanding. Sure you can prepay up to a certain extent. Eventually your domain will be available to others for purchase and therefore your accounts will become vulnerable. Maybe this isn’t an issue if in the worst situation you’re not around but if this could cause chaos for your friends and family I would suggest taking it into account.

>Eventually your domain will be available to others for purchase and therefore your accounts will become vulnerable.

what are you talking about? after I'm dead?

Re: Two billion email addresses were exposed

#465

Earlier quoted context omitted.

Thank you for expanding. Sure you can prepay up to a certain extent. Eventually your domain will be available to others for purchase and therefore your accounts will become vulnerable. Maybe this isn’t an issue if in the worst situation you’re not around but if this could cause chaos for your friends and family I would suggest taking it into account.

> Eventually your domain will be available to others for purchase and therefore your accounts will become vulnerable. what are you talking about? after I'm dead?

Any situation in which you fail to renew them.

Re: Two billion email addresses were exposed

#466

Earlier quoted context omitted.

> Eventually your domain will be available to others for purchase and therefore your accounts will become vulnerable. what are you talking about? after I'm dead?

Any situation in which you fail to renew them.

Given that domain renewals can be purchased multiple years into the future, along with the fact that there are grace periods after expiration, it would take an awful lot of failure to lose a domain unintentionally. I've held my primary domain since 1997 multiple registrars and numerous hosting / colocation arrangements over the years. It sounds harder than it is if you haven't done it before.

Re: Two billion email addresses were exposed

#467

Earlier quoted context omitted.

You need a domain, and possibly a paid mail provider with catch all support. So cost was always part of this strategy

The problem with catch-all inbox is when you have to reply to an email. Then you have to create the email address to be able to send emails from it. Or are there other solutions?

There's no solution to a non-problem. Precisely 3 of the hundreds of the generated email addresses I've given out over the past ~12 years have needed replies. When this happens, I simply reply from an address that actually does exist, while CCing the original generated address and setting it as the reply-to address.

If I ever have to give a generated address out to an actual person, then I'll let them know replies will come from a different address. So far I'd guess 99.999% of the emails I received are transactional emails and/or sent from noreply@...

Far more annoying are a few websites I use that only support magic links for login--my password manager doesn't auto fill them, and some of them I now have a number of accounts at due to inconsistent spelling/formatting.

Re: Two billion email addresses were exposed

#468

Earlier quoted context omitted.

I just use + @gmail.com At the end of day day it’s all delivered to myname@gmail.com mailbox, but I can use filters based on part after “+”.

I tried to start doing this. The first site I tried to sign up to said it was an invalid email address. I would say they could fuck all the way off, but there are legitimate reasons to not let people sign up with an alias (like one person signing up for multiple free trials)

There's other issues as well: occasionally a service will not allow using their service name in your email address. My usual response to this is to misspell it and use an address cursing them instead. (Since these accounts are usually one-off to register to view something, I really don't care if they delete my account in the future and I don't bother to save the password)

Re: Two billion email addresses were exposed

#469
post #324

Earlier quoted context omitted.

I used per-account email with alias services and password managers. Also started migrating old accounts in free time. Now its pretty easy to tell the source of leak by email addresses as well as sources of spam. --- Per-account alias might sound much, but using sieve filtering [1] is amazing, and you can get a comprehensive filtering solution going with 'envelope to' (the actual address receiving the email) + 'header…

> I used per-account email [addresses] with alias services I do too (anything@mysubdomain.example.com), but but online services collude with data brokers to share so much information [0] that I don't doubt that many of these "separate" profiles have been aggregated. Unfortunately the services that supposedly offer to have your personal data removed from data brokers don't seem to support aliasing, so no straightforwa…

> [0] Just look at the scary list of third-party cookies you can't opt out of on Coursera [1],

I can opt out of all of them. The only third party cookie I can't is a cloudfront one for crsf.

Re: Two billion email addresses were exposed

#470
post #469
post #324

Earlier quoted context omitted.

> I used per-account email [addresses] with alias services I do too (anything@mysubdomain.example.com), but but online services collude with data brokers to share so much information [0] that I don't doubt that many of these "separate" profiles have been aggregated. Unfortunately the services that supposedly offer to have your personal data removed from data brokers don't seem to support aliasing, so no straightforwa…

> [0] Just look at the scary list of third-party cookies you can't opt out of on Coursera [1], I can opt out of all of them. The only third party cookie I can't is a cloudfront one for crsf.

They've changed their cookie consent provider (or rolled their own) since my comment. Probably just a happy coincidence, but well done Coursera in any case for fixing a pretty egregious breach of regulations.

The other good news in the meantime is that the EU (who originally mandated cookie consent) has finally woken up to the ridiculousness of leaving it up to the site, and will require browsers to enforce it instead.

Post reply on HN