6 ms·
I have memories of this site providing me with an excellent experience. Now it's just a cash-grab, asking for $169.50/year just to see 100 breached accounts! I
by Sephr 3y ago
I have memories of this site providing me with an excellent experience. Now it's just a cash-grab, asking for $169.50/year just to see 100 breached accounts!
I use unique email addresses (breach canaries) on every website to detect when sites leak my data. When I tried to search for my domain results with a previous domain ownership verification, I got hit with this error: "In order to search a domain with any more than 10 breached accounts on it, you need a sufficiently sized subscription"
To make matters worse, Troy includes public data compilations as 'breaches' which artificially inflates counts for the breached accounts quota. For example, when a compilation of public contact details scraped from GitHub leaked, Troy counted that as a breach. I explicitly listed my email address as public.
I'd be willing to pay $5-12/year. These rates are outrageous for such a low-overhead service.
- benced 3y agoYou’re doing a weird thing (running your own email domain), doing an even weirder thing (using a different address per site), and then doing an even more weirder thing (scanning your personal domain for breaches) and your supposition is that very specific use case is a cash cow for Troy Hunt? Come on.
- Xorakios 3y agoIt is preferred practice, not a weird thing, to have a dedicated domain and a different address per site for anyone involved in online security research.
- dotancohen 3y agoI do the exact same thing. Every site, service, and contact gets a personal something@mydomain email address to reach me.
- cheschire 3y agoSomewhere in the distance, the Count from Sesame Street says "TWO... ah ah ah..."
- cqqxo4zV46cp 3y ago[flagged]
- Sephr 3y agoI said cash-grab, not cash cow. A cash grab is something that has an unreasonably high profit margin. A cash cow is something that provides a significant portion of an entity's income. I have no idea if HIBP is a cash cow for Troy. It may be, given these prices, but I don't know much about his other sources of income. HIBP didn't start out as a cash-grab, but it is one now. Troy could have chosen to price it reasonably to cover the costs of the service. This pricing is clearly taking advantage of HIBP's popularity as the de-facto breach list site.
- ehhthing 3y agoI can't tell whether this is a joke or not. I would bet you that over 99.99 percent of HIBP's users do not pay for the service. Troy's time has value, so working on a service that provides no income is not really something you can expect a person to do. Troy decided to create an enterprise subscription service to get a bit of revenue from something he's created. It's not cheap, but it's not something you're meant to buy unless you're a company looking to monitor your employee email addresses. This service is pretty cheap in that regard, actually. I really do not understand why you feel that you're being ripped off here. This is just a lack of product-user fit, his pricing structure simply doesn't work for you because you use email canaries. But for a company with 100 people, this pricing is entirely reasonable, if not something incredibly cheap. What you're paying for is everyone who doesn't pay for the service, the time he takes to add new breaches to the service and the time he takes to develop the service. Just because their pricing model doesn't fit you doesn't mean it's a cash grab. Is this too hard to understand? EDIT: Also, I assumed this was a common understanding, but product pricing is based on the value it gives to the person buying. For a company of 100 people, do you think paying $160/yr is worth breach monitoring? I think for any IT department, this would be a no-brainer.
- Sephr 3y agoThe cost of this service doesn't scale with number of 'breached accounts per domain'. Ideally, Troy should charge per domain and only choose a modest profit margin.
- rkagerer 3y agodoing an even weirder thing (using a different address per site) It should actually be considered best practice.
- tptacek 3y agoIt is not.
- _lvbh 3y agoI do the exact same thing minus the breach scanning. It’s not uncommon.
- stuckkeys 3y agoYou can download the DB from the DarkNet and run it locally so you don’t have to pay. The only downside is, you have to manage this db yourself and frequently update it. But it is similar. I have seen lot of these (cash-grab) services pop up offering API DB access for a cost.
- paulpauper 3y agothis is the way. you never want to alert someone to the fact your address is possibly vulnerable in the first place
- eganist 3y agoEncountered the same. My hope is that there's a pricing scheme for people like us; may be worth reaching out.
- aaronharnly 3y agoI’m in the same boat — not a company, just an individual doing the separate-email-per-site thing. (UPDATE): I’ve posted a suggestion to the UserVoice community, which it appears Troy actively monitors. If the several (dozens?) of us with this use case upvote it, it may catch his attention. https://haveibeenpwned.uservoice.com/forums/275398-general/suggestions/47530688-provide-a-subscription-level-for-individual-domain https://haveibeenpwned.uservoice.com/forums/275398-general/s...
- deleted 3y ago[deleted]
- aaronharnly 3y agoTroy responded: https://haveibeenpwned.uservoice.com/forums/275398-general/suggestions/47530688-provide-a-subscription-level-for-individual-domain https://haveibeenpwned.uservoice.com/forums/275398-general/s... Basically he suggested doing a monthly subscription for just one month periodically as a way to reduce the cost. Another option is to read the notification email, and if it’s for Acme Corp, to remember that the associated email must be acme.com@mydomain.com, and then manually check that.
- paulpauper 3y agoanother example of "everything as a service". Bullshit freemium model where a service starts out good, and then once they start getting usage: put the functionality behind paywall and degrade the free service to the point of being useless. Facebook, as bad as it is, has not succumbed to this: 'free Facebook' is still as functional as it was in 2010, but more tracking obviously.
- rkagerer 3y agobut more tracking obviously That's a price of its own.
- harshbutfair 3y agoI do the same thing. I wondered why I hadn't received any breach notifications for a long time, I don't remember seeing a notification of this change.