4 ms·
Does it mean your browser is going to leak your sites/account information to a third party? Will this feature be enabled by default? Can this be disabled?
by java-man 7y ago
Does it mean your browser is going to leak your sites/account information to a third party?
Will this feature be enabled by default?
Can this be disabled?
- SketchySeaBeast 7y agohttps://blog.mozilla.org/security/2018/06/25/scanning-breached-accounts-k-anonymity/ https://blog.mozilla.org/security/2018/06/25/scanning-breach...
- java-man 7y agothank you.
- snek 7y agohaveibeenpwned doesn't accept plain-text passwords for checking, they use a k-anonymity model to protect both your passwords and the passwords in the database. the same goes for email addresses. https://haveibeenpwned.com/API/v2#SearchingPwnedPasswordsByRange https://haveibeenpwned.com/API/v2#SearchingPwnedPasswordsByR...
- jsgo 7y agoHIBP doesn't work that way really. You don't query for a site breach + email combination, you basically give your email address and then it returns back a list of breaches your email address was part of. As far as HIBP linking your email to specific breaches, well, it is essentially using public data sets so that disclosure exists already (before HIBP even enters the picture). They are a bit more reserved with certain cases (the Ashley Madison breach for example), but even then if someone wanted to locate email addresses in that breach, they'd just go get that data set.
- java-man 7y agoAs long as this functionality can be disabled. This feature has a potential in connecting a browser (instance/session/ip) to an email (even in the form of abbreviated hash), which I would consider a security risk.
- groovecoder 7y agoAnswered here: https://news.ycombinator.com/item?id=20465981 https://news.ycombinator.com/item?id=20465981
- MrStonedOne 7y agoThey don't look at passwords They look at breached sites and rather or not you saved a login for that site on a date before the site was breached.