4 ms·
https://haveibeenpwned.com https://haveibeenpwned.com Make sure that you don't have any insecure accounts or reuse passwords that have been exposed through brea
by trishmapow2 9y ago
https://haveibeenpwned.com https://haveibeenpwned.com
Make sure that you don't have any insecure accounts or reuse passwords that have been exposed through breaches.
- IshKebab 9y agoReally annoyingly though they don't provide the hashes. I'd really like to know which passwords have been leaked. Does anyone know of a similar site that provides hashes? I don't need the complete list - just the hashes for my email.
- dublinben 9y agoWhat you're asking for is basically the full details of the data breach, which can be directly used to compromise accounts. You're not going to get that for free anywhere. You can check your own passwords (hashes recommended) through their new Password service. https://haveibeenpwned.com/Passwords https://haveibeenpwned.com/Passwords
- IshKebab 9y agoAh yes, type all my passwords into a third party network. I thought this was a site about good security. Also why wouldn't I get the full details for free anywhere? HIBP obviously has them. Criminals have them. I bet it isn't that hard to find them on bittorrent. In fact, here they are: https://hashes.org/public.php https://hashes.org/public.php Edit: Although that doesn't match them up with usernames, so it's not entirely useful. Edit 2: In fact I just discovered that a long password I used to use is still in the 'not cracked' category of the Last.fm leak (unsurprising since it is 13 random alphanumeric characters). That is useful information.
- Fnoord 9y agoI agree however then I reminded myself I shouldn't reuse passwords and ended up using unique passwords everywhere I remembered I reused passwords. A password manager makes it feasible to do that. Also enabled 2FA as much as I could (pref with an application on phone, otherwise SMS).
- doc_gunthrop 9y agoFor the site https://haveibeenpwned.com https://haveibeenpwned.com, does anybody happen to know if there is a quick and simple way to check email addresses that are one's regular email address with "+" and the service name appended? For example, given the email address generic@genericmail.com, if I were to sign up for facebook with generic+facebook@genericmail.com, does the HIBP site provide a simplified method for checking all variations?