For the people that use unique per-merchant e-mail addresses (like someone+amazon@...), could you try some of those aliases on HaveIBeenPwned and see which ones come up in this breach? That might shed some light onto its origin.
I suspect that Troy Hunt would have noticed if there were many emails with "+someservice" in the dump since he can easily dump them all.
The unattributable “db8151dd” data breach
61–70 of 155 posts
Re: The unattributable “db8151dd” data breach
#62Does elasticsearch have no authentication by default like mongodb or did someone deliberately make it public?
Re: The unattributable “db8151dd” data breach
#63I don't really get the utility of HIBP. The answer to the "have I been pawned?" question is, of course, yes, multiple times. I think about the only way to keep your email out of the hands of the bad guys is to not use it or give it to anyone ever, at which point you don't need an email address. What am I supposed to do whenever I'm involved in a new breach? Burn all my accounts and start again?
I mostly use it through 1Password, because it also notifies you when a service has enabled new security features like 2FA.
Re: The unattributable “db8151dd” data breach
#64Earlier quoted context omitted.
I am listed, but it's an address that was never used to register or subscribe to anything online. It's also under a year old. It must've been vacuumed up from other people's contact or email data.
Or from the email provider, if it's not your own server. I know that e.g. GMX has had a leak at some point (or sold data), as an email I created there ages ago was used in phishing. Okay, that's lame, but they've also used the fake name I had given to GMX, spelled perfectly. I've never used that name anywhere when signing up, so it must come from the database.
Re: The unattributable “db8151dd” data breach
#65Could it be Google+? 3 of 3 my Gmail addresses associated with their profile in some way were on it. Two of it I might have used to register a domain, but the last one I used for G+ and one other website only and none of any friends know this. Also I'm not in US or have US background, can't be from American friends' phones or retailer CRM.
Re: The unattributable “db8151dd” data breach
#66Does elasticsearch have no authentication by default like mongodb or did someone deliberately make it public?
Fixed now, but this was a common sequence of events at one time: https://discuss.elastic.co/t/ransom-attack-on-elasticsearch-...
Re: The unattributable “db8151dd” data breach
#67> Why load it at all? Because every single time I ask about whether I should add data from an unattributable source, the answer is an overwhelming "yes" To be fair, you’re asking your followers on twitter. That’s as biased as you can have, I would be really surprised if the majority would say no.
Re: The unattributable “db8151dd” data breach
#68Re: The unattributable “db8151dd” data breach
#69I don't really get the utility of HIBP. The answer to the "have I been pawned?" question is, of course, yes, multiple times. I think about the only way to keep your email out of the hands of the bad guys is to not use it or give it to anyone ever, at which point you don't need an email address. What am I supposed to do whenever I'm involved in a new breach? Burn all my accounts and start again?
And I think you’re about to describe Sign In with Apple.
Re: The unattributable “db8151dd” data breach
#70I don't really get the utility of HIBP. The answer to the "have I been pawned?" question is, of course, yes, multiple times. I think about the only way to keep your email out of the hands of the bad guys is to not use it or give it to anyone ever, at which point you don't need an email address. What am I supposed to do whenever I'm involved in a new breach? Burn all my accounts and start again?
Remember that most of us on here have extremely advanced knowledge of the Internet and its workings. This is not the case for the vast majority of Internet users.