5 ms·
I want the dump. I don't trust those pwn websites and I hold a multi gigabyte large breach dump myself for the last 15 years. Dumps should be made public, like
by underlines 6y ago
I want the dump. I don't trust those pwn websites and I hold a multi gigabyte large breach dump myself for the last 15 years.
Dumps should be made public, like exploits.
- underlines 6y agofound it a minute later on btdb. The data is really not interesting. It's like a 2021 version of a phonebook, that was common when I was younger. Where it becomes a slight bit dangerous, is that names and sometimes birthdates and emails are linked to it. username and SHA/MD5 password dumps are more interesting to analyze though.
- antpls 6y agoHow do you know it is the full data, and some of it was not removed ?
- koheripbal 6y agoWhile I do see the Facebook data here... I don't see other leaks. Have you found other leaks on btdb eu previously?
- linuxdesktopfo 6y agoIndeed, people assume haveibeenpwned is trustworthy when it seems to be a centralised place of valid emails from people that care about security and thus might have or control something of value?
- celticninja 6y agoI mean hibp is run by Tory hunt who has a good record as security researcher. So yes it's a centralised place but all it does is aggregate breaches and makes them searchable (to a degree, and not in a way that is useful for nefarious users). The breaches are not shared but those breaches are out there and nefarious users don't need hibp to get access to this data. It is really only useful to end users who want to see if they are at risk.
- linuxdesktopfo 6y agoWe don't know what that server is running. If it keeps a log of all the queries then it has a pretty nice list of emails from people that might make good targets.
- celticninja 6y agoGo read up about HIBP and Troy Hunt. It doesn't log requests, it tries to make it as difficult as possible for nefarious users to get any data from it. All the emails it checks are already included in public breaches which are available in the wild. You seem to be throwing shade at a service and person you haven't researched and all behind a new account. Very brave of you.
- linuxdesktopfo 5y agoI honestly don't care who this guy is. A centralised server providing this service is a problem. It's not like he is using some magic decentralised thing to run queries so we have mathematical proof nobody can aggregate data. No, it's a server he alone has root running whatever software. The notion itself of revealing info about you to a 3rd party in order to verify that more info hasn't been leaked seems... conflictual at some level. Your account presumably isn't new. Are you any braver?
- elwell 6y ago> haveibeenpwned is trustworthy It's not that hard to trust their honesty, the real question is will haveibeenpwned get pwned itself?
- ryankrage77 6y agoGiven that Troy is quite knowledgeable about how breaches happen, if HIBP does get breached, it will likely be due to targeted hacking rather than negligence.
- Gravyness 6y agoI also wanted the dumps but it seems only big players are allowed to "find" these dumps