6 ms·
Make sure you sign yourself up for something like https://haveibeenpwned.com https://haveibeenpwned.com if you haven't already. Sometimes being timely in respon
by oxplot 10y ago
Make sure you sign yourself up for something like https://haveibeenpwned.com https://haveibeenpwned.com if you haven't already. Sometimes being timely in responding to leaks can make a big difference on any further leaks.
- shostack 10y agoCan't upvote hard enough. Also, it is shocking how bad security is for all these games I've played over the years. The publishers seem to be the source of the vast majority of these leaks I've been caught in. Thankfully the notification emails from this service are prompt and helpful (not to mention totally free).
- thieving_magpie 10y agoAlso note the guy that runs it is the one that wrote this article.
- rajathagasthya 10y agoWow, thanks for this. I just found out that my email address was breached 3 times, while only one company sent an email informing me of the breach.
- hatsix 10y agoAlso, LastPass uses a similar site, plus it's specific knowledge of your passwords (last time it was changed), to let you know if a password has been compromised. Not sure if 1Password does as well, but it seems like a fairly obvious feature to add.
- irq 10y agoIt does.
- cmg 10y ago1Password has a "Watchtower" feature that "identifies websites that are vulnerable to Heartbleed". Also under Security Audit are sections for Weak Passwords, Duplicate Passwords, and groupings of password ages (3+ years old, 1-3 years old, 6-12 months old for me). It does not appear to keep track of leaks/hacks. https://watchtower.agilebits.com/ https://watchtower.agilebits.com/
- smsm42 10y agoThe problem with this feature seems to be that it thinks if the site reissues its certificate it means all passwords there were compromised. Which leads it to mark all old passwords as vulnerable, even if no breaches were actually reported for the site. The certificate/password link is a guess since on their website they say to change the password starting with date that matches the date of certificate reissuance. This seems to be related to Hearbleed, also it lists a site that didn't reissue certificate after Heartbleed as vulnerable too, and so for passwords there, seems to be regardless of age. I am a long-time 1password user and have a lot of old passwords, so for me like 90% of passwords are listed as compromised, which I'm pretty sure is not the case.
- thwarted 10y agoI'm not sure how much I can trust the results of a site that claims an email address I only use for one site has been breached on sites and services I've never been to. However it's calculating if what you enter into the form appears in the leaked content sure gives a lot of false positives. Which I suppose forces more awareness, but it doesn't instill a lot of confidence.
- wyldfire 10y agoI think false positives like this are worth reporting upstream. FWIW I was subscribed and didn't get anything until this most recent breach. Unfortunately GMail thought it was spam (speaking of false positives!).
- harlanlewis 10y agoA false positive from your perspective doesn't mean your email address isn't actually being used to sign up for things. My primary personal email address is routinely used by a small handful of other real people (all strangers) for all sorts of things - college applications, car insurance, some address books think it belongs to a cousin who gets included in a lot of group threads about reunions and full of photos. I've found the families more difficult to unsubscribe from than the services, name+email associations spread like a virus. I routinely get alarming/misleading "Someone has your password!" security alerts from Google after someone tries to list my email as a backup account. These little strings we use to identify ourselves can be typed by anyone, anywhere, bot or human. I wouldn't worry too much about false positives.
- thwarted 10y agoI wouldn't worry too much about false positives. It's not that I'm worried, it's that it's a distraction. When the margin of error is high enough, it becomes less signal and more noise, which leads to either panic (spending all your time managing access credentials) or complacency (ignoring the indicators).
- manishyt 10y agoI have the same problem. Do you have any suggestions on how to handle such emails?
- SerialBusiness 10y agoDamn, thanks for this. It seems that I've actually been pwned at some point.
- netule 10y agoThis was a strange way to find out that I have a Tumblr account.
- loeg 10y agoMyspace and Adobe, neither of which is present in my password manager. Huh, no memory of those.
- the_watcher 10y agoExactly my reaction.
- nissehulth 10y agoLol, that was my initial thought too. Also, I obviously once had an account on vBulletin.
- shaurz 10y agoI think there was a time when it was once considered a vaguely normal blogging platform.
- erikpukinskis 10y agoIt's abnormal now?
- narutouzumaki 10y agoHaha same here.
- DavideNL 10y agotrue... but unfortunately in this case (Dropbox) you would have gotten a notification about 4.5 years later ;-)
- nstj 10y agoFun fact: Have I Been Pwned neither salts nor hashes the creds which it stores on its website, potentially making itself an interesting target for hackers[0] [0]: http://risky.biz/RB388 http://risky.biz/RB388
- TazeTSchnitzel 10y agoHIBP doesn't store passwords, it only stores usernames and email addresses.
- tamana 10y agoHIBP hosts only completely Public alread leaked data -- that's how they source their data
- garaetjjte 10y agoI think it should hash entered email client-side in JS to be more trustworthy. I am a bit worried about giving my various email addresses to some random site.
- corobo 10y agoIf you don't trust it to keep your email safe why would you trust it when it says it's going to hash your address? Also it's an email address, not your credit card number.
- smsm42 10y agoIronically, https://haveibeenpwned.com https://haveibeenpwned.com certificate is signed by StarCom, which is the same as WoSign https://news.ycombinator.com/item?id=12411870 https://news.ycombinator.com/item?id=12411870 which means it basically trusts a known scammer to provide its security and one should not be giving this site any information you don't want to see in public.