Firefox Monitor
monitor.firefox.com
Firefox Monitor
1–10 of 10 posts
Re: Firefox Monitor
#2So it's exactly the same as https://haveibeenpwned.com/, except instead of giving hibp your email, you have to create a "Firefox Account".
I guess it comes down to whose 4000-word terms of service you like better.
Re: Firefox Monitor
#3It's a little less useful, since it won't shoot an email your way. But it's super handy to have a list of accounts/passwords/sites you need to change.
Re: Firefox Monitor
#4What's new here
Re: Firefox Monitor
#5Re: Firefox Monitor
#6This kind of data shouldn't be accessible by people who do not own the email address..
Re: Firefox Monitor
#7This kind of data shouldn't be accessible by people who do not own the email address..
People who create/release dumps that these tools check tend not to be too focused on account security....
Give me your email address and I can know your name + address + phone number + history of old passwords + browsing history and more personal data
But who am I to care about that kind of things, screw people right
Re: Firefox Monitor
#8This kind of data shouldn't be accessible by people who do not own the email address..
Also HIBP has a "domain search" for sysadmins: https://haveibeenpwned.com/DomainSearch
If you just want to check if the passwords of users of your service have been breached, there is a separate API for that: https://haveibeenpwned.com/API/v3#SearchingPwnedPasswordsByR...
Re: Firefox Monitor
#9Earlier quoted context omitted.
People who create/release dumps that these tools check tend not to be too focused on account security....
C'mon, there is a difference between breaching into servers and leaking/selling people's data and intentionally making all of that public and accessible through a public API Give me your email address and I can know your name + address + phone number + history of old passwords + browsing history and more personal data But who am I to care about that kind of things, screw people right
Re: Firefox Monitor
#10Earlier quoted context omitted.
C'mon, there is a difference between breaching into servers and leaking/selling people's data and intentionally making all of that public and accessible through a public API Give me your email address and I can know your name + address + phone number + history of old passwords + browsing history and more personal data But who am I to care about that kind of things, screw people right
Yeah let's give the bad guys all the ease of use while we put up obstacles for legitimate users
Wich explain the lack of care for privacy and security in the west, boy 2024 will be fun..
Privacy washing is a thing apparently