14 ms·
Authentication and the Have I Been Pwned API
- londons_explore 7y agoWho bruteforce scrapes the HIBP API across many IP addresses when they could just download the original leaked username & password databases? Theres even a torrent file of all of them I won't link here...
- rolltiide 7y agoTorrent file Of ALL leaks? I usually only see some And when people ask about a latest leak, others disingenuously reply “just check YOUR email on HIBP what kind of person needs the database”
- necovek 7y agoIf you run a web service and want to proactively expire breached passwords, you need to have full list of plain-text passwords to hash them with algorithm you are using (and use the same salt if you are doing that too).
- sleavey 7y agoMaybe spammers check if an email address is legitimate by checking HIBP. A pretty significant fraction of legitimate email addresses probably do show up in at least one list.
- floatingatoll 7y agoWhy download anything when you can simply query a public endpoint for free?
- abathur 7y agoThe compromised servers might be doing some primary work to which these queries are incidental, rather than for the purpose of scraping the database. In such a case, the API may be saving them from needing to build infrastructure to accumulate the database and either distribute slices of the data or host their own API for their distributed software to use. While the database may be valuable, they'd still have to invest a lot of time and some amount of money, face the same need to secure their API against exploitation by others, leave a stronger footprint leaving back to themselves, and have to depend on a service that is more likely to get flagged as a sure sign of suspicious activity than HIBP...
- Daviey 7y agoNext step, premium access without rate limit?
- yjftsjthsd-h 7y agoObvious next concern: Will bad actors just scrape the website? Putting authentication and payments in front of that rather defeats the entire point, and without that you're back to rate limiting which is exactly what has just been declared as a failed approach.
- abathur 7y agoProbably. But you can justify a significantly more restrictive rate limit for a website form intended for individual mortal humans to check their own personal email addresses for breaches. The API has to support request frequencies for legitimate usage that are obviously exploitable at a sufficiently small scale to attract a few exploiters...
- lightedman 7y ago"Will bad actors just scrape the website?" That's already been happening. Many simply use HIBP as a starting point to pwning someone's online accounts. Now, Troy is just going to attempt to really profit off of the actions of those bad actors.
- ec109685 7y agoOr scrape websites that provide a proxy to the API (e.g. the cloudflare worker he described).
- jawns 7y agoI wish the post made more clear, ideally right at the top, that the new fee applies only to third-party apps that access the HIBP API, not to end users whose email addresses are being checked against the API. You have to read through the post a bit before that becomes clear. Individual users who just want to figure out whether they've been pwned will not have to pony up the cash. They can still visit https://haveibeenpwned.com https://haveibeenpwned.com and get that information for free.
- badrabbit 7y agoDomain wide breach searches for a domain you control still appears to work for free as well.
- pixelbath 7y agoPerhaps it could be made more clear, but from the post I thought it was very apparent he was only talking about API abuse; most of the introductory text was concerning rate-limiting.
- nathan_f77 7y agoIt would also be great to emphasize that this only applies to the HIBP API, and the Pwned Passwords API will still be free. (It's mentioned about half-way through the article.)
- jrochkind1 7y agoHm, I didn't actually realize there was a separate Pwned Passwords API. Having trouble finding docs on it (could be becuase I'm a horrible googler).
- bpye 7y agoPwned Passwords is detailed towards the bottom of the API page - https://haveibeenpwned.com/API/v3 https://haveibeenpwned.com/API/v3
- Glyptodon 7y ago
- ksahin 7y ago"After 4 and a bit years, by far and away the most popular method with an uptake of more than 90% is versioning via the URL. So that's all V3 supports. I don't care about the philosophical arguments to the contrary, I care about working software and in this case, the people have well and truly spoken. I don't want to have to maintain code and provide support for something people barely use when there's a perfectly viable alternative." Well said !
- mehrdadn 7y agoFunny thing is here I am wondering why he didn't pass a query parameter instead of altering the path or adding a header to version the API... does anyone know? It has the advantage of being clickable while not implying the resource is different.
- floatingatoll 7y agoOne reason could be constructed by example, as: <Location /v3> vs. <LocationMatch ?[.*&]v=3(&|$)> Which is to say that, depending on the application's coincidental design and structural choices over time, managing versions at /v1 /v2 /v3 might well be vastly easier for the "shoestring budget" operator than at /?v=1 /?v=2 /?v=3.
- mehrdadn 7y agoIt seems unlikely considering the other 3 were more drastically different and yet seen as pretty equally easy.
- novaleaf 7y agoone benefit of putting version in the path is it makes it easier for loadbalancers to direct traffic. like v3 could be served from different servers than v2
- mehrdadn 7y agoWhy can't they do that with the query parameters?
- skybrian 7y agoVery understandable, and also yet another example of why we can't have nice services on the Internet. Traffic from bad actors pushes anyone offering an API in a similar direction, or discontinuing it altogether.
- w3rhn2j34oh5o 7y agoBoom, now Troy is monetizing stolen data. Unethical and illegal.
- mfkp 7y agoIt does cost money to run a service like this. He's historically had sponsors, but you can't expect someone to run a high traffic service for free forever.
- w3rhn2j34oh5o 7y agoAnd the local pawn shop has expenses too. Just because they have to pay rent and electricity costs does not make selling a stolen item legal.
- mfkp 7y agoThere's a difference - he's not selling the leaked passwords. He's selling the information that a password has been leaked for a certain account. You can't buy stolen passwords from the site, so it's perfectly legal.
- w3rhn2j34oh5o 7y agoI don't think it is that clear -- he is selling access to a data set containing PII (email address or account names). Its stolen data. One can make a case that free and open access to this data set is a common good, however once money is involved, one is conducting business with data that one did not legally obtain. It is not 'perfectly legal'.
- Aeolun 7y agoI don’t think the API ever returns that information. You need to already have the email address to be queried.
- sucrose 7y ago
- sroussey 7y agoMakes sense. I was writing an email to Troy that he can post about how to set custom user agent in Electron and Cordova, as the defaults fail. Guess it won’t be needed.
- theandrewbailey 7y ago> Making an authenticated call is a piece of cake, you just add an hibp-api-key header as follows: > GET https://haveibeenpwned.com/api/v3/breachedaccount/test@example.com https://haveibeenpwned.com/api/v3/breachedaccount/test@examp... > hibp-api-key: [your key] Wouldn't the standard Authorization: Bearer <key> header be more compliant?
- pionar 7y agoNo, because it's not a bearer token. Edit for clarity: A bearer token [0] is a concept for OAuth. This is not OAuth. [0] https://tools.ietf.org/html/rfc6750#section-1.2 https://tools.ietf.org/html/rfc6750#section-1.2
- Androider 7y agoOAuth doesn't have a monopoly on bearer tokens. And it is literally the definition of a bearer token: you shall know the messenger who presents this token, a concept old as history itself.
- y4mi 7y agoShould every OS which uses windows be able to call itself Windows, because windows are a quite old thing as well? Like it or not, there is an rfc for this and using it for anything else would be code smell at best
- patmorgan23 7y ago> Should every OS which uses windows be able to call itself Windows, because windows are a quite old thing as well? > Like it or not, there is an rfc for this and using it for anything else would be code smell at best No but every OS that uses windows can call them windows....
- y4mi 7y agoI guess they should be able to call them windows. Can you link to any tool which uses bearer tokens and doesn't grant them through oauth2? Or it's internal, please explain how the token is obtained. I haven't seen any to date but I guess I could be wrong
- sucrose 7y agoWhy are bad actors abusing the API? What benefit does it give them to just be able to check for leaked data on e-mail addresses? Especially when it doesn't actually provide the leaked data...
- birdman3131 7y agoAFAIK from looking myself up on the website before it tells which breaches to go hunt down for the actual info. Knowing they need to go hunt down the SpecificWebsite.com's March 2017 breach is way more specific than trying to have a database of all breaches.
- geddy 7y agoPerhaps they hammer it inefficiently or simply too often, possibly without even realizing it?
- smacktoward 7y agoNever underestimate the potential impact of stupid people in large numbers.
- HereBeBeasties 7y agoDoesn't take much imagination to find a use. Assume I find Anna's email address as part of a breach somewhere. Hello Anna, We value transparency and honesty highly at $p0wn3d_company. To that end, we're sorry to have to tell you that our systems were compromised by an unknown hacker recently. Although we believe that no personal data has been stolen, we are working with Government agencies and expert security consultants to determine the full extent of the breach. As a precaution we are asking our customers to change their passwords, which you can do by clicking on >this link here to a website that looks like ours but is actually owned by a hacker<. Etc.
- birdman3131 7y agoI find it ironic that a site dedicated to seeing if you have been compromised has no method of changing your API key if it is compromised.
- incidentnormal 7y agoEven though he explained why (it is likely a forthcoming feature), I did enjoy this comment.
- zxcvbn4038 7y agoAdding authentication so you know who is using your service is reasonable, but not sure why author is complaining about 1.2M requests per day, that is only 14 requests per second on average.
- mtmail 7y agoNear the top of the article it says peak 14k per minute (233 per second) and it sounds like demand is ever growing.
- floatingatoll 7y agoThey consider those requests to be "bad actors". It's not necessarily about the volume of traffic, it's that they are compromised VPSes configured to perform unknown malicious activity that takes advantage of a free endpoint in support of unknown malicious intent. See also "Why do bad actors abuse this endpoint?" discussion elsethread: https://news.ycombinator.com/item?id=20480230 https://news.ycombinator.com/item?id=20480230
- wolco 7y agoWouldn't most api traffic come from vps's regardless of the intent?
- floatingatoll 7y agoThe article notes that the VPS providers indicated that those top API traffic consumers were all a specific cron.php on compromised VPSes, so while in theory your statement is true, in reality the issue here was maliciously-compromises VPSes, not VPSes in general.
- dustinmoris 7y ago> One thing I want to be crystal clear about here is that the $3.50 fee is no way an attempt to monetise something I always wanted to provide for free. If this was true, then all revenue made from those 3.5 would get donated to a worthy cause, not donated into Troy's own pocket. I am not saying that he shouldn't monetise it, but please let's be honest about it. > The point is that the $3.50 number is pretty much bang on the mark for the cost of providing the service. The cost of the service is the actual final bill which has to be paid for this service, taken into account all the free credits Troy gets as a Microsoft Regional Director, free credits for hugely advertising Azure at every occasion, free credits from Cloudflare for constantly advertising for them, the tax which he doesn't pay as a registered company, etc. divided by the actual amount of customers who use the API. This cost could be much more, or significantly less than $3.5. If Troy wanted to be more transparent then he could, but given that he is very secretive and very selective about the bits of information he shares around all of this, my guess is the cost is much less than what Tory makes everyone believe. Overall I don't think it is ethical to monetise a service which is built on stolen data. There is a good chance that Troy holds data on me, my parents, my sister, wife and lots of other people who's data have been breached over the years and have no idea who Troy is, what the heck HIBP is or even know how to contest or request from Troy to remove their data from his service, yet it's being used for monetisation. There was never a consent from anyone to hord our data. It's stolen, and only because stolen data is easily discoverable on the internet doesn't make it alright to actively search, store and monetise that data. It's still stolen and should get deleted from everywhere.
- jtbayly 7y agoThis is such a clearly useful, legitimate service. You cannot tell the bad guys to delete your data. The next best thing is to be alerted when your data is found in a bad guy’s trove.
- wolco 7y agoJust because you have a legitimate reason doesn't mean everyone does. There are no bad guys just selfo serving people.
- DINKDINK 7y agoAll the ways congestion controls are implemented on the web lead to a cognitively infantilizing UX, privacy violations, and even "skynet" enabling[1] (hyperbolic but nothing stopping it from happening). "Are you really human? What's: 3 x 9" "Can you click on images of buses?, hmmmm don't believe you're human still, can you click images of stores, hmmm now bikes, hmmm now vehicles, oh I didn't mean all vehicles I just meant autos and not motorcycles, here quick copy this token, oh it expired? Too bad. How about you click on images of buses for me..." "Sorry, browsers that protect your privacy and location aren't allowed. We only allow users who are willing to deanonymize themselves." "Well we all know /those people/ who come /that place/ are antisocial users" "Here's your IP addresses back. Oh yeah, sorry about blacklisting them" This is a comment about the meta issue Troy faces. If costs are rubegoldberg'ed to create a facade of "free", it's not actually free (even if user data isn't being sold). e.g. A median-wage (10e3USD/year) world worker spending 20 seconds solving a captcha has an opportunity cost of 0.03USD[2]. Further more, having to solve congestion issues by implementing requirements to use closed/inaccessible (credit cards) poorly programmable, sucks too. Additionally, if a congestion solution is ("I'd rather low-demand users have free access and high-demand users have expensive access) isn't solved by having a flat rate (which a "keep it low cost, mantra is incentivized to keep low"). There is market demand for: If your demands on my service are x, I'll give you back the $3.50 but if you consume y resources You have to pay Z. Wouldn't it be great if there was a way machines could own money, send it over a layer-2 network, that was open, cheaper than credit cards, faster than L1 bitcoin, and get your money refunded if you didn't demand excessive server resources, all while not using game-able "good users come from here" privacy violating algos? This is why micropayment using layer-2 bitcoin on the Lightning Network has significantly-valuable, latent, economic-coordination implications. Micropayments aren't about paying for 1/1000 of a peanut. They're about obviating all the engineering, social, product costs dealt with dealing with Marginal Value, Marginal Cost issues. BAD: The marginal cost of anti-DoS counter measures can always be above the marginal value of deploying them ("listen folks it costs to much to keep this service running, we'll have to shut it down". UNSTOPPABLE: If a price is put on service requests (Services on Demand)[3] the marginal value will never be below the marginal cost ("I can keep this AED locator map service running because I know a spamming request will incur costs above my production costs"). In a future where L2 Bitcoin payment/Lightning client infrastructure is prevalent, gone will be the days of annoying, productivity-draining captchas, attribute-discriminating access. Troy could charged a 0.01USD "bond" payment for a request (Which he could give back fast and costlessly to a low-demand user). Meaning the 14e3/min requests for 3 hours would have required the high-demand user a payment of $25,000USD[4].\ 0.01USD refundable payment for honest users. $25,000 USD penalty for high-demand "spammer" [1] https://i.redd.it/pb5nggw3rulz.jpg https://i.redd.it/pb5nggw3rulz.jpg [2] 20/60/60 * 5 [3] https://medium.com/@soddiraju/the-not-so-micro-potential-for-micropayments-c581d3090d47 https://medium.com/@soddiraju/the-not-so-micro-potential-for... [4] 14e3 * .01 * 60 * 3
- zaroth 7y agoAll this seems to be hinting more than ever, that the time to provide these results directly and exclusively to the email address being queried is approaching. Why is this API being abused? Because it provides valuable information—which took a significant amount of effort to curate—about an email address. The list of services which have lost my (hashed or not) password at some point ever in the past eventually turns into a list of every service I’ve ever subscribed to. Whether or not it’s possible to scrape that information together, is it really something that should be available to pull over an API for a million emails a month? Note this is very different information than the password breach count, which gives you an approximate count of how many times a given password has been breached, and works as a proxy for password strength without disclosing any PII.
- jtbayly 7y agoYou’ve convinced me. I didn’t know anybody could lookup my info. I only want it for myself. Only thing is, there are a couple of old email addresses I used to use that I don’t have access to anymore. I guess I just need to shrug at that at this point.
- eli 7y agoThe bad guys have access to it either way. That's the whole point: this is data that already leaked.
- Nullabillity 7y agoLooks like AgileBits is getting scared.
- JoshTriplett 7y ago> Late last year after seeing a similar pattern with a well-known hosting provider, I reached out to them to try and better understand what was going on. I provided a bunch of IP addresses which they promptly investigated and reported back to me on I'd love to know how to get a hosting provider to actually answer such requests. (I hope the answer isn't just "be high profile". I'm hoping the answer is more like "know the right people to contact or the right phrasing to get through first-line support".) I've reached out to hosting providers before, providing clear logs of malicious activity, and either gotten no answer, or occasionally gotten a rote "prove it came from us" that would trivially have been answered by actually reading the logs. (Examples of such logs include SSH brute-forcing attempts, HTTP logs showing attempts to exploit web-app security holes, and spam headers showing the IP that contacted my provider's mail server.) I've mostly stopped even trying, due to the near-zero response rate. In an ideal world, I'd love to see reports like this lead to "we can confirm and we've shut down outbound traffic from that system until it gets fixed".
- coderholic 7y agoHow are you contacting them? If you use the correct abuse contact you'll usually get a response. We (IPinfo.io) are adding abuse contact info to our API within the next week or so (see https://twitter.com/ipinfoio/status/1138901541937602560 https://twitter.com/ipinfoio/status/1138901541937602560) - let me know if you'd like early access.
- JoshTriplett 7y agoTypically via abuse contacts or abuse forms. The only type of service providers I've ever had useful responses from are email/mailing-list service providers, many of which will very quickly investigate and terminate spammers.
- novaleaf 7y agoI feel his pain. I run a SaaS with what I think is a pretty generous free tier (PhantomJsCloud dot com), and yeah, I have numerous people from all over the world doing their best to shit all over it: - switching IP addresses every request to circumvent "demo user" rate limiting - creating upwards of 100 fake accounts to get free credits ($0.05/day each account) - embedding api calls into their webpages so their users ip address is used for "demo user" credits - API driven credit cards and hijinks around that. - using url shorteners to circumvent blacklisted domains I'm not sure if it's a case of people being incapable of paying credit cards, or just their ethics allow stealing anything that's not bolted down? I don't mind people signing up with a burner email address, but unfortunately most these abusers are too. I am going to be banning all throw away email accounts soon. And if that doesn't work (which it probably wont) I'm going to have to kill my free tier.
- peterwwillis 7y agoCan you do what the big cloud providers do, and demand a "real" phone number be verified for sign-up? Not impossible to beat, but more costly. Or maybe there's a market for paying customers somewhere between your free and paid tiers?
- novaleaf 7y agoMy lowest paid tier is USD$10/mth. As my target audience are developers, I think it's hard to believe that any of them would really be unable to pay that, yet still gain value from my service. Maybe I'm just a peace loving hippy but I'm rather shocked at the levels of abuse I see. I do want to enable paypal, just in case it's a lack-of-credit/debit card issue.
- w8rbt 7y agoI obtain the SHA1 hashes published by HIBP, load them into a bloom filter and use that for checks. It's super fast (constant time lookups) and avoids a network dependency/third party service. Here's working Go code: https://github.com/w8rbt/bp https://github.com/w8rbt/bp Edit: This is solely for password vetting during account creation and password reset (which will remain free/no-cost in the API).
- elamje 7y agoI wonder if this actually has more to do with trying to sell HIBP, than abuse. He just announced that he was selling HIBP a month or two ago. Presumably, if he can get people to pay a nominal fee now for access to the api, it makes HIBP much more valuable to a potential acquirer. If you can prove people are willing to pay $.01/month for a subscription, you can assume(as a potential acquirer) that they would pay $.02/month in the future. Much harder to sell something that is completely free because of the risk that monetization completely fails later. In previous blog posts he mentions that he gets 99.x% cache hits on Cloudflare, then also has a cache on his Azure service. He is sponsored by Cloudflare and Microsoft and doesn’t pay for the service unless something has changed since a few months ago. If that is still true, I don’t fully buy that he is actually spending money on Microsoft api hits as the post claims. But, I like Troy and HIBP, so maybe I’m just too much of a skeptic :-)
- Aeolun 7y agoI don’t use this API myself, so it doesn’t really effect me, but this somehow feels like one of the last purely good things was lost.