Live data from Hacker News

The unattributable “db8151dd” data breach

troyhunt.com

51–60 of 155 posts

Re: The unattributable “db8151dd” data breach

#51
post #2

For the people that use unique per-merchant e-mail addresses (like someone+amazon@...), could you try some of those aliases on HaveIBeenPwned and see which ones come up in this breach? That might shed some light onto its origin.

My gmail is on it, but not my burner-domain. So either the data is old (year or two), or they got my gmail from somewhere else.

I'd be interested to see the whole dump to see my full record...

Re: The unattributable “db8151dd” data breach

#52
post #2

For the people that use unique per-merchant e-mail addresses (like someone+amazon@...), could you try some of those aliases on HaveIBeenPwned and see which ones come up in this breach? That might shed some light onto its origin.

I did, and I usually use site specific emails (eg amazon@username ) but it found my "generic" firstname@username email... So no insights there.

Re: The unattributable “db8151dd” data breach

#53
post #11

Earlier quoted context omitted.

BTW, since many people don't seem to be aware of this: If you have your own domain, you can get informed by haveibeenpwned automatically if any mail address from that domain is in a breach. All that is required is that you're reachable on that domain through an address like 'postmaster'. This feature can be found under 'domain search'. Since I use a new address for pretty much anything this is very handy.

Unfotunately, it no longer seems to list the impacted email addresses in those domains have been comprimised, so it's not too useful.

I've found it does list them if you request the full report, but that the initial email doesn't. (note the last time I used this functionality was about 3 weeks ago, I accept it may have changed since then)

Re: The unattributable “db8151dd” data breach

#54

Dataset for sale: [redacted] Similar data structure: https://stackblitz.com/edit/angular-soswe4?file=src%2Fapp%2F... Owner works for: https://covve.com Covve: This simple yet state-of-the-art app will revolutionise your business relations like you've never seen. Edit: Response: https://twitter.com/covve/status/1261287954967941120

The responses to the comment just below you (https://news.ycombinator.com/item?id=23190102) (and the nature of some of the corporate hits I've seen) seem to be consistent with a contacts database of sorts.

Not sure I'd go so far as to accuse a specific company on a public forum. But in this regard, the idea that a contact management app could be behind this DB is plausible.

Re: The unattributable “db8151dd” data breach

#55

Dataset for sale: [redacted] Similar data structure: https://stackblitz.com/edit/angular-soswe4?file=src%2Fapp%2F... Owner works for: https://covve.com Covve: This simple yet state-of-the-art app will revolutionise your business relations like you've never seen. Edit: Response: https://twitter.com/covve/status/1261287954967941120

Forked the stackblitz for posterity https://stackblitz.com/edit/angular-3nxvlm?file=src/app/app....

Re: The unattributable “db8151dd” data breach

#56

Earlier quoted context omitted.

Thanks for saving me a click. No desire to play "guess how many minutes I'll have to spend clicking sidewalks" today.

If it takes you minutes to solve a recaptcha your problem might not be the recaptcha...

You tend to see a whole lot more challenges if you're on a VPN. It taking a couple of minutes isn't at all implausible.

Re: The unattributable “db8151dd” data breach

#57
post #2

For the people that use unique per-merchant e-mail addresses (like someone+amazon@...), could you try some of those aliases on HaveIBeenPwned and see which ones come up in this breach? That might shed some light onto its origin.

I suspect that Troy Hunt would have noticed if there were many emails with "+someservice" in the dump since he can easily dump them all.

Re: The unattributable “db8151dd” data breach

#59
post #11
post #2

For the people that use unique per-merchant e-mail addresses (like someone+amazon@...), could you try some of those aliases on HaveIBeenPwned and see which ones come up in this breach? That might shed some light onto its origin.

BTW, since many people don't seem to be aware of this: If you have your own domain, you can get informed by haveibeenpwned automatically if any mail address from that domain is in a breach. All that is required is that you're reachable on that domain through an address like 'postmaster'. This feature can be found under 'domain search'. Since I use a new address for pretty much anything this is very handy.

Wow, thanks so much, that's really helpful!
Post reply on HN