Live data from Hacker News

Firefox Monitor

monitor.firefox.com

71–80 of 227 posts

Re: Firefox Monitor

#71

So basically if I put somebody's email address I could know the sites they have logged in in the past? And then I can use the leak and get access to their account? Shouldn't this information be mailed to the email address queried rather than displaying upfront

As topranks mentioned, all this data is already available and anyone could download it.

However, in most leaks, you can't just use the information as the passwords are (hopefully) hashed/salted. That said, it is trivial to crack md5 if passwords are stored using that method.

Also, not all leaks contain passwords, some might just be lists of email addresses or other information.

Re: Firefox Monitor

#72
post #55
post #39

My email appears in six breaches. Only one of the companies I recognize. I have never done business with the other five. This pisses me off. Not that the data was stolen -- these things happen. It pisses me off that my data was shared with third parties without my knowledge or consent. And no, a paragraph buried in the basement of a privacy policy does not constitute informed consent. This system would be more useful…

> I want to know who betrayed me. You can run your own email server (or have a company host a private domain for you), set up a catch-all address that only you know, then use a different email address for every site you sign up to. That way you can find out this sort of information. Using this technique, I know for example that spammers obtained the address I signed up to Stack Overflow with. The email is not shown o…

I do this with Fastmail, including specialized subdomains to help me segment the addresses and then distinct email names for each sign up as necessary.

You can also do something similar with Gmail (and probably other providers) using "+" in your username, e.g. "myname+hackernews@gmail.com". This creates a unique email address that delivers to your Gmail account as if the "+" were absent. This is more easily defeated if you're a moderately motivated spammer.

Re: Firefox Monitor

#73

I checked my email address and it says my data was lost by verifications.io. I've never heard of that site before and going there didn't reveal any clues. I googled the name and found a report [1] on the breach. They lost control of records on 2 billion email addresses. [1]: https://www.forbes.com/sites/daveywinder/2019/03/10/2-billio...

It sounds like this was email addresses only, and they're very shady about how they acquired this information in the first place.

"The real question that the researchers and Troy Hunt, founder of Have I Been Pwned?, want to know is how Verifications.io got its hands on all of this information in the first place. The Estonian-based company has refused to respond to questions from different news outlets and has taken down its entire website as of March 4, 2019. " [1]

and

"Verifications.io ensures third-parties’ email marketing campaigns are being sent out to verified accounts, and not just fake emails. " [1]

[1]: https://www.idtheftcenter.org/763-million-records-exposed-in...

Re: Firefox Monitor

#74
post #55
post #39

My email appears in six breaches. Only one of the companies I recognize. I have never done business with the other five. This pisses me off. Not that the data was stolen -- these things happen. It pisses me off that my data was shared with third parties without my knowledge or consent. And no, a paragraph buried in the basement of a privacy policy does not constitute informed consent. This system would be more useful…

> I want to know who betrayed me. You can run your own email server (or have a company host a private domain for you), set up a catch-all address that only you know, then use a different email address for every site you sign up to. That way you can find out this sort of information. Using this technique, I know for example that spammers obtained the address I signed up to Stack Overflow with. The email is not shown o…

Fastmail supports this natively (and is awesome). You can do service@user.yourdomain.com and it will get delivered to user+service@yourdomain.com.

Re: Firefox Monitor

#75
I bought extended car warranty from a company and they subsequently exposed my VIN, name and email on a publicly shared DB by accident, and its still up. I don't want to report this to them directly. Anyone know if I can report this to Firefox Monitor somehow?

Re: Firefox Monitor

#76
post #53
post #30

Earlier quoted context omitted.

Not everything needs to be a "big tech company", but you are right big tech companies are quite similar in this respect. At critical mass capitalism seems to cause companies to lose their driving principles that made them unique - their behaviour becomes more of a mindless ecology driven solely by money. Now look at Mozilla, it's a non profit, look at everything it does, they have never lost their principles. They wi…

The downvotes might be because you responded to a request for more detail with: > I don't think I need to explain what those are... Why don't you humor us and give some examples anyways?

https://www.cbc.ca/news/thenational/complete-control-apple-a...

This is just one example, In general when Apple hardware fails from any kind of defect, one of two things happens:

1. They blame the customer and suggest replacing large portions of the computer (unnecessarily) at such a high cost as to justify recommending buying a new machine.

2. In the rare cases they have been publicly pressured into admitting fault, they will replace parts with newer parts with the same defect and repeat this cycle until out of warranty or the customer just gives up.

For the cases where the user is to blame for damage, #1 is also applied, this would not be such an issue if Apple wasn't also lobbying against independent repair shops and seizing their parts under false claims of trademark violations.

They are deceitful... there is no way around it.

Re: Firefox Monitor

#77
post #55
post #39

My email appears in six breaches. Only one of the companies I recognize. I have never done business with the other five. This pisses me off. Not that the data was stolen -- these things happen. It pisses me off that my data was shared with third parties without my knowledge or consent. And no, a paragraph buried in the basement of a privacy policy does not constitute informed consent. This system would be more useful…

> I want to know who betrayed me. You can run your own email server (or have a company host a private domain for you), set up a catch-all address that only you know, then use a different email address for every site you sign up to. That way you can find out this sort of information. Using this technique, I know for example that spammers obtained the address I signed up to Stack Overflow with. The email is not shown o…

gmail's +suffix is a great built-in tool to achieve this. E.g. me@gmail.com and me+stackoverflow@gmail.com route to the same destination. Sadly I've seen services that do not accept pluses in a email address

Re: Firefox Monitor

#78
31 breaches on my Gmail account that I've had for close to 15 years.

I'm actually surprised it's not more given how many sites/forums/services I've shared this with over the years.

Re: Firefox Monitor

#79

Disclaimer: Firefox Monitor dev here. Note: We just released a "V2" of the site that allows you to add multiple email addresses to monitor, and (then) to have all your breach alerts sent to your single primary email address.

Oh the irony if my email becomes breached for using Mozilla's service.

In all seriousness I have faith in you guys for the most part (storing my bookmarks and sharing the browsing sessions across browsers).

Re: Firefox Monitor

#80
post #21

Apparently MyFitnessPal had their data breached, and my email address/password was in it. Checking my emails, I can't see anything from them about this. Loads of the usual marketing crap, but nothing about a breach. Not cool!

Same, for me it was them and Apollo. I can't find anything about either of them in my mail, but both claim to have notified their customers. That's very suspicious. I don't delete anything... Perhaps it found its way into my spam and got auto-deleted (entirely possible with Apollo, seems very unlikely with MFP).
Post reply on HN