4 ms·
How is it legal for HIBP to keep copies of breach corpuses on their servers? For me personally, having corpuses on my hard-drive is like dealing with radioactiv
by cyberlab 6y ago
How is it legal for HIBP to keep copies of breach corpuses on their servers? For me personally, having corpuses on my hard-drive is like dealing with radioactive waste. There's so much PII to mull over that it feels naughty to sift through. There's even people on social media bragging about 'self doxing' their own info (just like with using HIBP), but using a local copy instead.
- nathanfig 6y agoI presume they keep a table mapping email addresses to breaches and that's it.
- cyberlab 6y agoYes but how is it legal to have multiple corpuses sitting on a gigantic server? Surely governments or even a LEA would want to regulate that? Having all that PII is like hoarding a bunch of radioactive waste.
- wan23 6y agoThey don't need to keep the data around longer than it takes to extract the affected email addresses, and that doesn't need to be done on a server at all.
- philjohn 6y agoDo they store the full breach there, or is the PII put through a one-way hash and that used for matching?