Live data from Hacker News

Should I Change My Password?

shouldichangemypassword.com

51–60 of 104 posts

Re: Should I Change My Password?

#51
post #6
post #3

The site should treat @gmail.com and @googlemail.com as equal. I found my leaked MtGox mail address for one variant but not the other.

username+randomstring@g[oogle]mail.com should be normalized to username@gmail.com, as well. I used a custom extension for MtGox that wasn't found. That said, really useful service. On the other hand it's sad that we actually need something like this.

Technically, username+randomstring@* should be normalized to username@* ; plus in email address is part of the standard.

Re: Should I Change My Password?

#53

Earlier quoted context omitted.

In HTML5, both the and tags are completely optional, as are their closing tags. Since there's no other content on this "page", you don't need to close the header either, so you could replace everything with: YES

The title tag is required, though (unless you’re in an iframe), and an h1 tag must be closed (unlike, e.g., paragraph and list item tags). So your minimal page looks like: YES YES

Really?

http://validator.w3.org/check?uri=http%3A%2F%2Funitinu.net%2...

http://validator.w3.org/check?uri=http%3A%2F%2Funitinu.net%2...

http://validator.w3.org/check?uri=http%3A%2F%2Funitinu.net%2...

Dang, apparently so. Guess I was wrong.

The world's most inane objection: If you force the validator to HTML5 mode, (as in the first and second links) then you don't need to declare a DOCTYPE, a savings of 16 bytes. Not that you would ever do that for a real document, since it's a dumb idea.

Re: Should I Change My Password?

#54

It'd be cool if they added an option to subscribe for $10/year for a quick SMS and email notification if your account is compromised. I'd get it for myself and my family.

"Here is the password I use for potentially important information, and here is the email and phone number that would likely be associated with that password. Let me know when your database get's hacked so that way I can change my password and we can do this exercise again."

Something like that you mean?

Re: Should I Change My Password?

#55

Strangely, the exact moment I received the email from mtgox, gmail told me I have to change the password. I wonder if they had a trigger for that message, or did someone really try to access my account (different password, so very unlikely)

The Gmail team downloaded the database of mtgox user account information that was leaked, matched gmail addresses to gmail accounts, and then proactively notified those Gmail users to change their passwords.

Nice timing then. I was browsing my gmail and at the same time received mtgox notification on my mobile and got locked out on the browser - assumed the notification email was a trigger.

Re: Should I Change My Password?

#56
I guess extreme caution is good. But saying to somebody Your email, username, and password have been compromised" strikes me as a little sensational.

Granted, the average user doesn't need to know or understand the vagaries of password hashes. But if somebody reads this, they should think "OMFG somebody can login to my email account!" I mean, that's exactly what it says. But there's no legitimate reason to believe that.

Moreover, if you look at MtGox, Google locked every account on that list and forced people to change their passwords. But if you're Joe User looking at this today, are you going to connect the dots enough to see that yes, you WERE in a data leak, but then you changed your password, but this site just didn't know about it and is informing you only of the leak?

Re: Should I Change My Password?

#57

It'd be cool if they added an option to subscribe for $10/year for a quick SMS and email notification if your account is compromised. I'd get it for myself and my family.

"Here is the password I use for potentially important information, and here is the email and phone number that would likely be associated with that password. Let me know when your database get's hacked so that way I can change my password and we can do this exercise again." Something like that you mean?

You don't need to give them your password or phone number, just the email address associated with your account(s). Adding a phone number would be optional.

Re: Should I Change My Password?

#58
post #17

so, can someone answer this for me? I have a personal domain on google apps. The login ID is different than the email address I use/advertise. e.g. my username for login is first-initial+last-name@[domain].com But the email address I use for everything on that account is first-name@[domain].com This service states that my account was compromised on 12/12/2010 most recently at the first-name@[domain].com though you co…

It's referencing these sources: https://shouldichangemypassword.com/sources.php To me this means that my password is out there, and now a part of someone's dictionary. Change all places where that password is used immediately. I am currently moving to LastPass with randomly generated 16-32 char passwords for every site. It's less of a pain than one might think.

Curious...

It says it's using the perlmonks.org database, and I _know_ my password was revealed there (thanks to me foolishly reusing it on twitter), but it's not showing that against my email address...

Re: Should I Change My Password?

#59
post #42

Earlier quoted context omitted.

So any Google-served address is marked as vulerable because of the Gawker hack?

No, the google address is a red herring. My non-google account is listed as compromised on the same date due to a Gawker account I had registered. Many google accounts were compromised in other events on other dates.

My mistake. I thought my Gawker account was on another address, but a quick search shows I got the hint.io mail on 12/13.
Post reply on HN