4 ms·
It's amazing. Just about every single one of my email addresses have been compromised in one way or another, how could it be there are so many websites with suc
by Kequc 10y ago
It's amazing. Just about every single one of my email addresses have been compromised in one way or another, how could it be there are so many websites with such bad security.
- pg_is_a_butt 10y agoor, you're just attracted to bad websites. the problem is likely with you.
- cloudjacker 10y agoThat site is amazing, I can look up anyone's email address and see what hacked communities they are a part of
- deleted 10y ago[deleted]
- rahkiin 10y agoWell, the data is already on the internet...
- cloudjacker 10y agoit is more convenient, just upvote and move on
- gambler 10y agoUnless they use different emails for different websites. This sounds extreme, but you just pointed out one reason that might be a good idea.
- cm2187 10y agoAnd other reasons include: Knowing who leaked your email or sold it to spammers Being able to stop spam by deleting the email You could even consider binding the email to a domain so the address would only accept emails from the domain you gave this email address. You don't really want different mailboxes, you want one mailbox with different aliases. An alias becomes a "communication token" which can be revoked, very much like when paypal gives a payment authorisation token to an ecommerce website. If that token gets leaked, no big deal, no one else can use it. A single email address is more like a credit card number.
- imtringued 10y agoTry <username>+<per_site_suffix>@gmail.com and then set up a filter for every suffix. The per_site_suffix can be anything you want.
- cm2187 10y agoExcept that everyone does that, I am sure spammers very well know that suffix trick.
- tjohns 10y agoBecause security is actually really hard, contrary to popular opinion. As an industry, I think we need to rethink the way we develop, package, and deploy web apps. The fact that we rely on individual developers and sysadmins to get security right, perfectly, every time is crazy. In an ideal world the prod environment should protect me from shooting myself in the foot, and the OS should be running a hardened-by-default, single-purpose system image that doesn't require bespoke knowledge to make secure. While far from perfect, I think the PaaS vendors (AppEngine and Heroku) got a lot of things right in this regard. [Disclaimer: I work for Google, but not on Google Cloud.]
- cm2187 10y agoNo. Most vulnerabilities are sql injections and phishing attacks. There are so many leaks because incompetence is the norm among developers.
- ssharp 10y ago> Because security is actually really hard, contrary to popular opinion. But some of the password hashing algos used, no salting, making all password characters lower-case in the background, etc. are not hard things to avoid. So when a site is hacked and the user information stolen and we find that stuff out, it's safer to assume other security practices where also subpar.
- iLoch 10y agoYup there are just a lot of bad developers out there, quite honestly.
- dvhh 10y agoAdd "cheap" to their traits, and it would help figure out why anybody would ask them to code anything
- ssharp 10y agoFor big sites, I have a hard time blaming it on a bad developer. Early in my career, I worked for a company that stored it's passwords in plain-text. I suggested on many occasions stop doing this and was always told no because the site had an older audience and they wanted to make it easy to send password reminders, which also meant they were emailing passwords in plain-text. This came from the tech director and CEO and none of the other devs seemed to care. A few years after I left, their DB was compromised, so someone got a list of email addresses with clear text passwords.