Live data from Hacker News

Firefox Monitor

monitor.firefox.com

51–60 of 227 posts

Re: Firefox Monitor

#52
post #2

How does this relate to HaveIBeenPwned.com? Is it a separate effort? Does it have more data? Is it built on top of their data? I've seen other services (like 1Password) just rely on HaveIBeenPwned because it's pretty solid – seems like it would be nice for the industry to coalesce around it and build these kinds of alerting features on top of it.

I'm pretty sure it's a partnership with HaveIBeenPwned: https://www.troyhunt.com/were-baking-have-i-been-pwned-into-... > We're Baking Have I Been Pwned into Firefox and 1Password > Over the coming weeks, Mozilla will begin trialling integration between HIBP and Firefox to make breach data searchable via a new tool called "Firefox Monitor".

Great News! I looked for that on their site but may have missed it.

Re: Firefox Monitor

#53
post #30

Earlier quoted context omitted.

I can’t think of a big tech device company that’s any less driven by money than apple. What makes them so unique, in your mind? In my experience I’ve had less unwanted tracking and advertising, and better support compared to other phone and laptop manufacturers I used to buy from.

Not everything needs to be a "big tech company", but you are right big tech companies are quite similar in this respect. At critical mass capitalism seems to cause companies to lose their driving principles that made them unique - their behaviour becomes more of a mindless ecology driven solely by money. Now look at Mozilla, it's a non profit, look at everything it does, they have never lost their principles. They wi…

The downvotes might be because you responded to a request for more detail with:

> I don't think I need to explain what those are...

Why don't you humor us and give some examples anyways?

Re: Firefox Monitor

#54
So, an email address I use for messaging only has appeared in an "Apollo" breach. It's nice to have your data floated around by some dick companies that specialise in "sales intelligence".

Wtf?

Re: Firefox Monitor

#55
post #39

My email appears in six breaches. Only one of the companies I recognize. I have never done business with the other five. This pisses me off. Not that the data was stolen -- these things happen. It pisses me off that my data was shared with third parties without my knowledge or consent. And no, a paragraph buried in the basement of a privacy policy does not constitute informed consent. This system would be more useful…

> I want to know who betrayed me.

You can run your own email server (or have a company host a private domain for you), set up a catch-all address that only you know, then use a different email address for every site you sign up to. That way you can find out this sort of information.

Using this technique, I know for example that spammers obtained the address I signed up to Stack Overflow with. The email is not shown on my profile now, and I can't rule out that it wasn't ever shown publicly, but evidence suggests they sold my address to spammers. I also know that spammers crawled my website and found a blog post where I stupidly made up a random address using my domain as part of an example for configuring junk filters (the irony is not lost on me).

Re: Firefox Monitor

#56
post #48

Disclaimer: Firefox Monitor dev here. Note: We just released a "V2" of the site that allows you to add multiple email addresses to monitor, and (then) to have all your breach alerts sent to your single primary email address.

Nice work! Small suggestion -- it would be nice to be able to to have the notification sent to the breached email and the primary email

Good idea. File it here? https://github.com/mozilla/blurts-server/issues

Re: Firefox Monitor

#57
Are they doing anything with the email addresses beyond checking they appear in breach databases ? Are they anonymizing things, for example using some kind of one-way hash to match email addresses ? Is it GDPR-compliant ? There is not clear explanation of how they're processing that data as there should be as email addresses are personal information.

Re: Firefox Monitor

#59

If it's using the haveibeenpwned service then why does it say my email has been found in less number of data breaches compared to the number on the haveibeenpwned site (11 vs 14)?

By default we don't show:

* Sensitive Breaches * "Retired" Breaches * Spam Lists * Fabricated Breaches * non-Verified Breaches

https://github.com/mozilla/blurts-server/blob/master/hibp.js...

Re: Firefox Monitor

#60
post #57

Are they doing anything with the email addresses beyond checking they appear in breach databases ? Are they anonymizing things, for example using some kind of one-way hash to match email addresses ? Is it GDPR-compliant ? There is not clear explanation of how they're processing that data as there should be as email addresses are personal information.

https://blog.mozilla.org/security/2018/06/25/scanning-breach...
Post reply on HN