3 ms·
My problem with haveibeenpwned is that when you haven't been pwned, you've just handed them your mail address. Is there anything to alleviate those concerns ot
by yAnonymous 8y ago
My problem with haveibeenpwned is that when you haven't been pwned, you've just handed them your mail address.
Is there anything to alleviate those concerns other than "trust us, we're not saving emails from queries"?
- superflyguy 8y agoI think a lot of people have my email address. You don't hear people worrying about spam so much these days (other than people who have the time and inclination to run their own mail servers). So it would seem to be a small price to pay to keep tabs on your passwords.
- oblio 8y agoWell, if you don't trust them, obviously just don't use it. If you do half-trust them, if they're reasonable, they don't store the email addresses. They don't need to, for a simple search.
- auslander 8y ago> just don't use it But the post is about integrating it into the browser, isn't it?
- Piskvorrr 8y agoWhich is exactly why the service won't query the plaintext, or even a complete hash.
- auslander 8y agoBut how do I keep not using it?
- oblio 8y agoThe same way I don't use Pocket or the Edit Controls in Firefox, or Pivot Tables in Excel. You don't click them :)
- auslander 8y agoIts all about defaults, what matters most, as it'll be used by majority of users. People will use whatever pops up or was put on taskbar.
- oblio 8y agoAgreed. However, for the average user, I think the risk posed by this new Firefox feature is smaller than the risk they're exposing themselves through ignorance.
- auslander 8y agoDisagree. Respectfully :) Today we have age of free data harvest, 'land grab' by majors. Shining combination of your email, IP and user-agent as a default browser behaviour is just another leak.
- Piskvorrr 8y agoAgain: no-email-exposed-never-not-even-encrypted-or-hashed. So just an IP address and user agent; if that is a leak, I would recommend disconnecting from the network altogether.
- Piskvorrr 8y agok-Anonymity. In other words, "I have hashed my e-mail address, here's the beginning part of the hash: 0deadbeef0, tell me if you have anything matching that." "Yup, I have something that hashes to 0deadbeef0123456789abcd, associated with these breaches, and something else that hashes to 0deadbeef0abc1056886516, associated with those breaches." Plaintext is not exposed, and you're not even exposing the whole hash, so GL to anyone trying to find out which if the hashes (if any) is yours, let alone what the plaintext was. https://blog.mozilla.org/security/2018/06/25/scanning-breached-accounts-k-anonymity/ https://blog.mozilla.org/security/2018/06/25/scanning-breach...
- yAnonymous 8y agoSeems like a good solution. I was looking for this on the official HIBP website, but it's not mentioned there. Going public with this would probably be a good time to update the website.
- cricalix 8y agoRead https://www.troyhunt.com/were-baking-have-i-been-pwned-into-firefox-and-1password/ https://www.troyhunt.com/were-baking-have-i-been-pwned-into-... as well.