18 ms·
Firefox Monitor
- goda90 7y agoLooks like this doesn't include another feature of HaveIBeenPwned. Its cracked password hash database. If you trust their JavaScript, you can type in your passwords and see if they are on the list. If you're a little more paranoid you can download the hashes and do your own search.
- kibwen 7y agoSince this service appears to be deliberately aimed at non-tech-savvy users, I get the impression that Mozilla is trying to not normalize the practice of submitting your passwords to third-party websites. It also nimbly sidesteps any questions of "why should I trust firefox.com with my password"; you don't need to, because you're not giving it to them.
- ZeroGravitas 7y agoMozilla have a password saving app, not checked but I wouldn't be surprised if that is a feature and may have inspired this collaboration.
- JeanMarcS 7y agoWell with the API it’s pretty easy to test your password. You just have to hash it, send the 5 first characters and it returns the list of the hashes starting with those 5 characters. You then just check.
- TremendousJudge 7y agoIt's easy if you know what you're doing. I don't think my mother could do this.
- JeanMarcS 7y agoYou are completely right, but I was answering to parent post. I don’t think your mother, or mine, can ask herself this question of trusting the JavaScript or not :-)
- groovecoder 7y agoDisclaimer: Monitor dev here ... Watch this space: https://github.com/mozilla/blurts-addon/issues/142 https://github.com/mozilla/blurts-addon/issues/142 ;)
- rhamzeh 7y agoThat repo is archived and read-only though. Is it still being actively developed elsewhere?
- atonse 7y agoHow does this relate to HaveIBeenPwned.com? Is it a separate effort? Does it have more data? Is it built on top of their data? I've seen other services (like 1Password) just rely on HaveIBeenPwned because it's pretty solid – seems like it would be nice for the industry to coalesce around it and build these kinds of alerting features on top of it.
- faitswulff 7y agoI'm pretty sure it's a partnership with HaveIBeenPwned: https://www.troyhunt.com/were-baking-have-i-been-pwned-into-firefox-and-1password/ https://www.troyhunt.com/were-baking-have-i-been-pwned-into-... > We're Baking Have I Been Pwned into Firefox and 1Password > Over the coming weeks, Mozilla will begin trialling integration between HIBP and Firefox to make breach data searchable via a new tool called "Firefox Monitor".
- atonse 7y agoGreat News! I looked for that on their site but may have missed it.
- raisedbyninjas 7y agoAt the bottom of the results page: Breach data provided by Have I Been Pwned
- lifthrasiir 7y ago> Is it built on top of their data? Yes. # How does Firefox Monitor know my information was hacked during a particular breach? Firefox Monitor gets its data breach information from a publicly searchable source, Have I Been Pwned. If you don’t want your email address to show up in this database, visit the opt-out page. https://support.mozilla.org/en-US/kb/firefox-monitor-faq https://support.mozilla.org/en-US/kb/firefox-monitor-faq
- deleted 7y ago[deleted]
- 7y ago
- 123jay7 7y ago"This email appeared in 17 known data breaches." How does this help at all? What can I do about it? Some of the breaches are years old...
- cmg 7y agoFirst, if you know you've reused a password on one of the services listed, then you know to go change that password everywhere. Everyone should be using unique passwords and a password manager, but some of these breaches are so old they're before that was a commonly-used practice. Second, you can look into each incident to see what exactly was breached -- personal information, payment info, and so on. It's good information to know.
- groovecoder 7y agohttps://monitor.firefox.com/security-tips#after-breach https://monitor.firefox.com/security-tips#after-breach
- darkhorn 7y agoChange all your passwords with randomly generated passwords. https://password.generator.app/ https://password.generator.app/
- Scrantonicity 7y agoPrevious discussion: https://news.ycombinator.com/item?id=18067049 https://news.ycombinator.com/item?id=18067049
- yuchi 7y agoMozilla and Apple, lately, are the only companies I trust my data to. Nice to see more from both.
- tomxor 7y agoI find it difficult to trust Apple for security considering their morally bankrupt behaviour in rest of their business. They have proven their sole principle is monetary, so I find it difficult to perceive their recent claim to care about user security as anything beyond opportunism.
- charles_f 7y agoA large chunk of their marketing nowadays is around privacy and it looks like it's more and more in their priorities, and Apple is a company that has historically loved by suckling at their customers sweet wallety nectar. So yeah even if they're driven by money, their best interest is aligned with their customers'- living up to the promise that your data is yours with them. The other thing is that there seems to be a better chance at being private with a company that does not start its promise by telling they want to know everything about you and "index the world"
- lallysingh 7y agoYup. They're in privacy because their biggest competitor is Android and this is their best angle. Tech advancements for phones are ho-hum at this point, so this is how they compete with carrier-based incentives for android phones on upgrade. That's all fine and good, but privacy is a float, not a bool, and let's not assume Apple's going to go any further than they have to. They won't ever ask their users to do something inconvenient to get better privacy. They're not discussing specific threat models that they're trying to protect their users against. Just features that they support in specific use cases. Which may sound like a hollow problem, but it leaves each user to deal with understanding all the threats they're under and what measures they should take. That's fertile ground for an adaptive adversary to work with.
- ilikehurdles 7y ago
- criddell 7y agoI checked my email address and it says my data was lost by verifications.io. I've never heard of that site before and going there didn't reveal any clues. I googled the name and found a report [1] on the breach. They lost control of records on 2 billion email addresses. [1]: https://www.forbes.com/sites/daveywinder/2019/03/10/2-billion-unencrypted-records-leaked-in-marketing-data-breach-what-happened-and-what-to-do-next/#366401d06b0d https://www.forbes.com/sites/daveywinder/2019/03/10/2-billio...
- jmkni 7y agoI'm in that list as well, don't remember ever signing up for it.
- ilikehurdles 7y agoSeems like all the cold calling useless recruiters and sales people built up extensive databases on their clients via this company and then promptly let all that data leak.
- luizfzs 7y agoSame here
- tomstockmail 7y agoI had similar with a website called Apollo. Story linked below[1]. Edit: Their opt out page and main site[2]. Notably, Firefox Developer Edition warned me and linked me to the main Firefox Monitor page, so it's something that's being built into Firefox. [1] https://www.wired.com/story/apollo-breach-linkedin-salesforce-data/ https://www.wired.com/story/apollo-breach-linkedin-salesforc... [2] https://www.apollo.io/privacy-policy/ https://www.apollo.io/privacy-policy/
- asauce 7y agoInteresting, thanks for linking the story. I also had the same experience with Apollo. Its frustrating since I never signed up for their services, and I have no control over who my data is sold to... Its getting to the point where I just assume all my data is pwned, and change passwords frequently
- jmkni 7y agoApparently MyFitnessPal had their data breached, and my email address/password was in it. Checking my emails, I can't see anything from them about this. Loads of the usual marketing crap, but nothing about a breach. Not cool!
- steve_adams_86 7y agoSame, for me it was them and Apollo. I can't find anything about either of them in my mail, but both claim to have notified their customers. That's very suspicious. I don't delete anything... Perhaps it found its way into my spam and got auto-deleted (entirely possible with Apollo, seems very unlikely with MFP).
- znelis 7y agoI got a notification from Myfitnesspal titled "Important Message Regarding MyFitnessPal Account Security", so they at least sent out some.
- ata_aman 7y agoAlso got mine leaked from FitnessPal and Apollo and them only. No idea what Apollo is or how they got my stuff. Any idea what it is? A link to each service's website would be awesome in the breach report on FireFox Monitor.
- mh- 7y agoHad the same. Seems Apollo is https://www.apollo.io https://www.apollo.io - you were probably entered as a sales lead.
- parliament32 7y agoI found the email: From: "MyFitnessPal" <donotreply@mfp.underarmour.com> To: [me] Subject: Important Message Regarding MyFitnessPal Account Security Date: Thu, 29 Mar 2018 18:18:57 -0600
- benatkin 7y agoI really wish Firefox would focus, and I don't mean Firefox Focus. If they focused on making it simple, fast, and reliable, it would have a much better shot at taking market share from Chrome. On top of that, I wish everything on top of a browser was truly optional - that they didn't have reminders of sync spread throughout the app, and that they didn't have a Pocket button in the toolbar unless I logged in with Pocket. "Find out what hackers already know about you." unnecessarily grinds my gears, as a hacker (programmer) who wants Firefox to succeed.
- retSava 7y agoPerhaps this is their focus. Not FF monitor, but privacy. Going up against/with Apple as a privacy-conscious alternative to Chrome etc. From that viewpoint, this is in line with that.
- benatkin 7y agoIt's currently taking away from it being a good browser. When I go to a new site I get this atrocious animation: https://superuser.com/questions/1438488/disable-firefox-content-blocking-shield-animation https://superuser.com/questions/1438488/disable-firefox-cont...
- emn13 7y agoYou may find your priorities as to what constitutes a good browser are not universal. Having a content blocker may be more important to many people than a tiny animation most people will barely notice. And... if you're not immediately used to a content blocker it's not a crazy idea to have something that actively draws a tiny bit of attention to the fact that something altered the page you saw, because content blockers do sometimes break pages, and thus users need to be able to find a way to disable it, certainly while the feature is still fairly new. I think it's fair to say that you're never going to find a set of features and UI that have universal appeal, but if the UI really distracts you even after the first few times (I honestly don't notice it anymore), you could suggest a feature that allows disabling the icon or at least turning off the animation. Sounds like a reasonable request to me at least...
- user17843 7y agoHave I been pwned prompted me to abandon my old addresses and switch to a provider that allows trash mails and email aliases. Originally my address was breached by Dropbox and Kickstarter. It took me many months to switch over, as I did not have a complete list of all services I had registered with. So for many average people switching email adresses is often a very difficult task, so people keep them even in light of breaches. More important for the average user is to have a good password management system and know whether a certain password has been hacked.
- hestefisk 7y agoI was on 8fit, a fitness app. Was never notified of any breach. Lame.
- brianbreslin 7y agoDoes this have an API? I would pay a nominal amount to have this tied to my 1password DB to crosscheck all the emails I use. Since I use a different email for each site, I'd like this automated. Also do you think this is the same value as LifeLock?
- darkhorn 7y agohttps://haveibeenpwned.com/API/ https://haveibeenpwned.com/API/ https://1password.com/haveibeenpwned/ https://1password.com/haveibeenpwned/
- mikeiz404 7y agoThe footer of the results list says “Breach data provided by Have I Been Pwned” and it looks like Have I Been Pwned has an API here https://haveibeenpwned.com/API/v2 https://haveibeenpwned.com/API/v2. I personally don’t see a benefit to Firefox Monitor, aside from a new channel of exposure and branding for Firefox, if they are providing the same data Have I Been Pwned is.
- frosted-flakes 7y agoTrust. Mozilla is a relatively well-known trustworthy entity. "Have I been Pwned" sounds like some shady website that will steal your data. I've certainly never heard of it before, and Random Randy definitely won't have.
- orbz 7y ago1password already is integrated with Have I Been Pwned, which sounds like the same dataset that this is using. I believe it's exposed via Watchtower in the app. (https://1password.com/haveibeenpwned/ https://1password.com/haveibeenpwned/)
- leeoniya 7y agowould be a lot more helpful if it clarified if it's hashed passwords or plaintext, also if they were hashed with a site-wide salt or per-user salt. imo, this distinction is too important to be omitted from a short summary.
- mhaymo 7y agoWhy is it important? In either case, the correct course of action is to treat the password as insecure.
- groovecoder 7y agoDisclaimer: Firefox Monitor dev here. Note: We just released a "V2" of the site that allows you to add multiple email addresses to monitor, and (then) to have all your breach alerts sent to your single primary email address.
- athorax 7y agoNice work! Small suggestion -- it would be nice to be able to to have the notification sent to the breached email and the primary email
- groovecoder 7y agoGood idea. File it here? https://github.com/mozilla/blurts-server/issues https://github.com/mozilla/blurts-server/issues
- mikaelmello 7y agoAre there plans to monitor an entire custom domain?
- programbreeding 7y agoI would love this as well. I use website-im-on@mydomain.com for every login. Being able to monitor my entire custom domain would be great. I assume it would require some sort of DNS verification or something.
- Fogest 7y agoJust use the site where Firefox is getting their data from, they have a domain feature: https://haveibeenpwned.com/DomainSearch https://haveibeenpwned.com/DomainSearch
- mothsonasloth 7y agoOh the irony if my email becomes breached for using Mozilla's service. In all seriousness I have faith in you guys for the most part (storing my bookmarks and sharing the browsing sessions across browsers).
- ccleve 7y agoMy email appears in six breaches. Only one of the companies I recognize. I have never done business with the other five. This pisses me off. Not that the data was stolen -- these things happen. It pisses me off that my data was shared with third parties without my knowledge or consent. And no, a paragraph buried in the basement of a privacy policy does not constitute informed consent. This system would be more useful if it could report how these companies got my data. I want to know who betrayed me. It wouldn't be a terrible thing to have privacy legislation that forces companies that sell your data to disclose what information they sold, when, and to whom.
- rishabhsagar 7y agoSo, I 100% agree with you and think a sentence in multi-page privacy policy is not informed consent. Recently in EU GDPR regulation brought in some strict measures on how consent is requested and how data is shared and managed, I was delighted when websites started sending me emails asking me for content to market and share data. However I am now seeing a bunch of websites doing the shady tactic of showing a full page pop-up on mobile site with all 30+ checkboxes pre-ticked allowing them full access of my data. Fuck such sites.
- stevesimmons 7y agoThose don't meet the required standard of "an unambiguous indication by clear affirmative action" according to the UK ICO's interpretation of GDPR: https://ico.org.uk/for-organisations/guide-to-data-protection/guide-to-the-general-data-protection-regulation-gdpr/consent/how-should-we-obtain-record-and-manage-consent/ https://ico.org.uk/for-organisations/guide-to-data-protectio... "You cannot rely on silence, inactivity, pre-ticked boxes, opt-out boxes, default settings or a blanket acceptance of your terms and conditions."
- sneak 7y agoWhat kind of world do we live in where using a free service and agreeing to explicitly documented T&Cs doesn’t constitute acceptance? “You provided a contract, and I agreed even though I chose not to read it (despite you providing it), and used the service, but I didn’t really mean to agree” is the most ridiculous cop-out, in my view.
- deleted 7y ago[deleted]
- bcaiv 7y agoThis is basically a frontend for haveibeenpwned. Creating it costed Mozilla money. Why did they do this instead of linking directly to the original page?
- proaralyst 7y agoBecause the Mozilla brand is more trusted than a random website with ‘Pwned’ in its name. Also, it's being built into Firefox so having a website for it too seems like a good idea.
- Fogest 7y agoWell the have I been pwned website is also pretty trusted and is integrated into 1password. I don't know why Firefox wouldn't just integrate it into the browser like 1password did with their password manager. Would make more sense than just being a different front end to an existing site.
- lotu 7y agoPwned is not a standard english word. The vast majority of non-tech non-gamer non-under 40s are unfamiliar with this word but are familiar with firefox.
- Fogest 7y agoYou think people of that age are familiar with what a "Fire fox" is? With all the people I've helped most don't even know a browser outside of the default on their system.
- djsumdog 7y agoYea that's what I noticed. Do they use any additional sources at least?
- jmichaelhudson 7y agoI don't know, but they are going to have to find something to do with all of those email addresses in a database connected to the source vectors. btw: the nsa tracks people by email address, as in, according to snowden, that is an often used search term to pull up all the surveilled data on an individual. /s
- lux 7y agoIt would be helpful to include a link to the services somewhere. I only figured out this was for apollo.io because of a comment on HN: https://monitor.firefox.com/breach-details/Apollo https://monitor.firefox.com/breach-details/Apollo
- roryokane 7y agoI agree, it would be helpful. At least Firefox Monitor does give you a way to find more details, by linking to https://www.haveibeenpwned.com/ https://www.haveibeenpwned.com/. If you click from that page to https://haveibeenpwned.com/PwnedWebsites https://haveibeenpwned.com/PwnedWebsites and search the page for a company name, you will find more details about it.
- miguelmota 7y agoIf it's using the haveibeenpwned service then why does it say my email has been found in less number of data breaches compared to the number on the haveibeenpwned site (11 vs 14)?
- groovecoder 7y agoBy default we don't show: * Sensitive Breaches * "Retired" Breaches * Spam Lists * Fabricated Breaches * non-Verified Breaches https://github.com/mozilla/blurts-server/blob/master/hibp.js#L142-150 https://github.com/mozilla/blurts-server/blob/master/hibp.js...
- sleepybrett 7y agoOh damn, I thought, based on the name, that this would be a better firefox task manager .. you know, one that actually functions. Nope.
- skilled 7y agoSo, an email address I use for messaging only has appeared in an "Apollo" breach. It's nice to have your data floated around by some dick companies that specialise in "sales intelligence". Wtf?
- ajnin 7y agoAre they doing anything with the email addresses beyond checking they appear in breach databases ? Are they anonymizing things, for example using some kind of one-way hash to match email addresses ? Is it GDPR-compliant ? There is not clear explanation of how they're processing that data as there should be as email addresses are personal information.
- groovecoder 7y agohttps://blog.mozilla.org/security/2018/06/25/scanning-breached-accounts-k-anonymity/ https://blog.mozilla.org/security/2018/06/25/scanning-breach...
- groovecoder 7y agoAlso, https://www.mozilla.org/en-US/privacy/firefox-monitor/ https://www.mozilla.org/en-US/privacy/firefox-monitor/
- jmichaelhudson 7y agoThey have the fish in the barrel, so I am figuring that this is the next step in that process. The fish who have any chance of escaping the barrel will likely be attracting the most attention...and other things.
- meh206 7y agoMozilla really wants your information these days :(
- freewilly1040 7y agoHow do you mean? All they are collecting is your email, and the whole point is to show you that your email (and much more) is already in the wild
- jmichaelhudson 7y agoThe other response to this is...wow, 'all they have is your email address' snowden: 'all i needed was your email address to pull pull up all your entire surveillance record' hackernews: propaganda shilling? never heard of it.
- roca 7y agoThis is a useful service that can help improve security for a lot of people. If you don't want to use it, fine, ... don't use it.
- mangatmodi 7y agoSo basically if I put somebody's email address I could know the sites they have logged in in the past? And then I can use the leak and get access to their account? Shouldn't this information be mailed to the email address queried rather than displaying upfront
- topranks 7y agoIt’s already publicly available in the dumps Mozilla are searching on your behalf. They’re only making a front end to already public info.
- kuzimoto 7y agoAs topranks mentioned, all this data is already available and anyone could download it. However, in most leaks, you can't just use the information as the passwords are (hopefully) hashed/salted. That said, it is trivial to crack md5 if passwords are stored using that method. Also, not all leaks contain passwords, some might just be lists of email addresses or other information.
- mangatmodi 7y agoThis is about making is easier to attack a particular person, but privacy concern. Breaks the anonymity on internet.
- lotu 7y agoThis is a fair point and it has to be weighed against the value of the data to the individual. I generally feel they have struck the correct balance but if you think different approach is warranted you should explain it and why it better balances these different needs.
- kuzimoto 7y agoThe companies that were responsible for the data in the first place are ones to blame for breaking "the anonymity on internet". Anything that anyone does after the fact is moot.
- aeonsky 7y agoI bought extended car warranty from a company and they subsequently exposed my VIN, name and email on a publicly shared DB by accident, and its still up. I don't want to report this to them directly. Anyone know if I can report this to Firefox Monitor somehow?
- r3bl 7y agoSend it to Troy Hunt: https://www.troyhunt.com/contact/ https://www.troyhunt.com/contact/ He's behind Have I Been Pwned, and Firefox Monitor is an alternative interface for it. I believe he verifies the breaches by contacting a few people in a new breach that have already signed up for HIBP notifications.
- Goronmon 7y ago31 breaches on my Gmail account that I've had for close to 15 years. I'm actually surprised it's not more given how many sites/forums/services I've shared this with over the years.
- emn13 7y agoThat's only the big ones you know about; it's safe to say there have been many many more smaller ones; especially if the site was small or desperate enough to consider a coverup.
- EasyTiger_ 7y agoApollo whom I've never had any dealings with whatsoever have compromised my details. Absolutely fucking outrageous.
- tuxone 7y agoSame here, I never heard of Apollo and I have 0 emails from them in my email account. Yet it looks like they leaked both email address and (and this sucks a lot) phone number.
- albertgoeswoof 7y agoIf you really want to avoid this, use a different email address for every service you sign up for. Here’s something I made earlier that helps with this: https://idbloc.co https://idbloc.co
- m52go 7y agoLooks like Mozilla is starting to break out again, and it seems they're making the most of it with recent headlines. I say they should capitalize on it with the ultimate announcement. Bring back Firefox OS!
- deleted 7y ago[deleted]
- rgblambda 7y agoTried my email address. Only leak was due to Warframe (which I've played a total of 15 minutes of back in 2014). Tried my parents email accounts and both had zero breaches. I know for a fact my mother's email account has been in at least one data breach so I'm questioning the comprehensiveness of this tool.
- cparsons3000 7y agoIsn't this the same as https://haveibeenpwned.com/ https://haveibeenpwned.com/?
- c0vfefe 7y agoYes, that's their data source.
- aquova 7y agoOut of curiosity, is there a list somewhere of utilities like this that are run by Mozilla/Firefox? I don't think I would've heard about Monitor or Lockwise if I hadn't been on here when someone had posted it, so I'm curious if there are other useful services by them that I have missed.
- bwat49 7y agoNot sure if there's a full list anywhere, but Firefox Send is another nice one
- ksec 7y agoSometimes I wonder if it would be easier if we just start anew. I cant go back and change every single password with that email address that I didn't use KeyChain before.
- brians 7y agoThis is fantastic work, and sets the problem out with high resolution and clear contrast. Pity the stand costs so much.
- emanreus 7y agosergey@google.com in 7 breaches larry@google.com in 14 breaches
- loop0 7y agoIt looks like they don't have the Onliner Spambot database, as my email is not flagged but when I look at the haveibeenpwned website it flags for this spam list.
- danarel 7y agoMy data was leaked in Verifications.io's breach and I don't think I have even heard of this company...
- huehehue 7y agoThere are just so many problems. Traditional authentication methods have failed us. I'm still waiting for a reasonable alternative, but the best we've come up with are things like 2FA and magic links? Companies insist on sucking as much data out of their users as possible. What are your options? Hand over your personal information and give hackers a reason to attack your favorite services? Create a million different phone numbers, burner addresses, and fake personas? How exhausting. Then there's the problem of treating data like SSNs, phone numbers, and legal names as private. These things could be public if central authorities could do their jobs correctly, but we've shifted the blame of e.g. "identity theft" to the end user who ultimately has no control over this stuff. Further, official ID/passport/etc. scans are required of so many transactions and I guarantee my slumlord does not follow good security practices so what can I do other than sit like a duck? Monitors like this are a noble effort, and I'll definitely use them, but it sucks that it's come to this.
- Mistri 7y agoI don't understand what the point of this is. HaveIBeenPwned exists, they acknowledge (and use) their service, and offer the same exact services as they do. What's the point? It's just a reskin.