3 ms·
What if the opt out list gets pwned?
by coolcase 1y ago
What if the opt out list gets pwned?
- eddythompson80 1y agoI assume if that ever happens, someone will register https://haveibeenpwnedbyhaveibeenpwned.com https://haveibeenpwnedbyhaveibeenpwned.com. It'll be the top post of HN for a couple of says while everyone argues in the comments about how the state of online security is "fundamentally broken" while someone asks if they can sue. Then we'll all forget and move on.
- YPPH 1y agoI'm surprised Troy Hunt hasn't defensively registered this. Compare https://troyhuntsucks.com/ https://troyhuntsucks.com/
- TonyTrapp 1y agoI think there was an earlier blog post from Troy sometime ago describing that HIBP never stores unencrypted email addresses; i.e. they are all hashed and any lookups go against the hash, not the actual email address.