5 ms·
The downside to having many vanity urls and giving out a unique email address to each website you visit is that you cannot use haveibeenpwned without paying (de
by worldfoodgood 11mo ago
The downside to having many vanity urls and giving out a unique email address to each website you visit is that you cannot use haveibeenpwned without paying (despite being a single human). I have no idea how many email addresses I've given out over the years, probably hundreds across at least 6 or 7 domains, and they want to charge me a monthly fee to see which of those have been pwned.
I understand they gotta make a buck, but I find it interesting this is the first real negative to running a unique email address per company/site I work with.
- SoftTalker 11mo agoJust assume they have all been exposed. Email addresses are not secrets under any stretch of the meaning of that word.
- deleted 11mo ago[deleted]
- worldfoodgood 11mo agoIt's not the email address itself that I care about, and that's not the service that the site provides. It tells you for which email addresses a related password has been pwned.
- EvanAnderson 11mo agoI'm in the same boat. I track all of the unique addresses I use (via my password manager) so I guess I could just check them all against HiBP's database. Kind of a pain in the ass, though.
- warkdarrior 11mo agoMy password manager (Bitwarden) does that automatically.
- EvanAnderson 11mo agoI use Bitwarden with a Vaultwarden server so I have some familiarity. Bitwarden checks new passwords against HiBP. I'm not aware of functionality where it can retroactively check old email addresses or passwords to see if they're included in a breach.
- lern_too_spel 11mo agoIt's under Reports: https://bitwarden.com/help/reports/ https://bitwarden.com/help/reports/
- EvanAnderson 11mo agoAhh, okay. I assume that's a part of the Bitwarden offering, presumably happening server-side. I'm just using their official client w/ a Vaultwarden server.
- jorams 11mo agoIt is also available in the Vaultwarden web interface (which is just a rebranded Bitwarden web interface).
- Beijinger 11mo agoenpass.io does this automatically if you selected the option.
- mindslight 11mo agoMe too. It used to work for whole domains. Then I guess the limit was added as part of some kind of monetization push. I don't derive enough value to pay for a monthly subscription any time it occurs to me to check, nor figure out how to check addresses one-by-one programatically. So the site is basically dead to me now. It's a shame because there were a few breached lists where people were speculating on where exactly they came from, and I was able to add to the discussion based on which of my tagged addresses were in the list.
- EvanAnderson 11mo agoI've had that experience re: my personalized addresses being used to more closely identify the source and time of a breach. When I start getting spam to one of my personalized addresses I'll usually reach out to the party for whom the address was created to let them know. Usually I get treated like a crank but occasionally I get somebody who understands and appreciates the help.
- huijzer 11mo agoIsn’t the idea that you don’t need haveibeenpowned since you’ll see mails coming in and then know your details have leaked? For ID fraud, more than an email address has to be leaked.
- worldfoodgood 11mo agoHave I been pwned will tell me if the associated password for that site leaked. I create unique passwords per site, but lets say my mastercard login gets pwned -- that'd be one I want to change the password for right away. I might not get an email if someone gets that account info.
- dpoloncsak 11mo agoIn theory, I agree. In practice, anything that high-profile will be plastered all over every tech news site, twitter, reddit, probably even the news. It would be difficult for MasterCard/Visa to have dataleaks, even just email/pass, fly under the radar (I imagine...) Oracle tried to cover up a data leak, and it didn't go great. Oracle touches nowhere near as many every-day people as MasterCard does
- kccqzy 11mo agoThe domain search feature on haveibeenpwned is/was free. I registered my domain on haveibeenpwned back in 2017 and I got two emails about breaches, one in 2020 and another in 2022. I did not pay.
- EvanAnderson 11mo agoIt tells you that an address in your domain has been included in a breach. It doesn't tell you which address was included. That's what the OP and I are opining about.
- osculum 11mo agoIt does. I just checked mine today. I can see exactly which individual email addresses in my domain where exposed and in which data leak. I have never paid for it.
- EvanAnderson 11mo agoInteresting. I'd love to see where you're seeing that. I'll go poke at the site a little more. Edit: When I try to do a domain search I get told: > Domain search restricted: You don't have an active subscription so you're limited to searching domains with up to 10 breached addresses (excluding addresses in spam lists). My domain has 11 breached addresses.
- osculum 11mo agoI log in. Click on Business -> Domains. Then click on the looking glass under "Actions" on my domain. I can there see all my addresses an Pwned Sites. But I think you are right, because I only have 3 breached addresses under my domain (I do see the 10 addresses wording under subscriptions)
- toast0 11mo agoYep, if you have the good fortune of having many breaches while using companname@example.org, the service requires that either you pay up or you have to guess and check. I understand, but it's frustrating.
- deleted 11mo ago[deleted]
- ekjhgkejhgk 11mo agoI don't understand... The password is the secret, right? If your mastercard login ends up in some breach, your password is protecting. You without or without vanish urls, if you have strong passwords you'll be fine.
- XorNot 11mo agoCybercrime has a logistics pipeline. Harvesting potential targets is one part of it i.e. establishing someone was using an email address is the entry point. There's a lot of emails, so associating them to any particular website is right near the start. Establishing that they're active increases their value further. The people responding to Troy here for example are technically doing that: they clearly monitor the email or still use it, so addresses which respond to up in value.
- guelo 11mo agoI have the more typical one email used with hundreds of passwords on many websites. haveibeenpwned is also useless for me, it will tell me that my email was compromised but not which sites or passwords. I guess I could check each password individually, hope each password is globally unique to me, and then try to match it back to the website where I used it so I can change the password.
- NetMageSCW 11mo agoIf you don’t know which web site uses a particular password, how do you ever login to that website?
- worldfoodgood 11mo agoReread the parent post more closely. It does not tell them: A) which site nor B) which password. The parent can log in because they have a map of site<->password. But without either the site or the password, the notification that an email address is compromised is useless.
- TZubiri 11mo agoYou need a domain, and possibly a paid mail provider with catch all support. So cost was always part of this strategy
- worldfoodgood 11mo agoI have those things? Did you miss the part where I have multiple vanity URLs and hundreds of email addresses? Of course I have a paid mail provider and catch all. The problem is the cost of haveibeenpwned is too much for me as an individual.
- TZubiri 11mo agoYeah I get it. I meant that you are already paying for those, so being charged by providers to support our hacky email addresses is not a novelty introduced by Troy's service
- ycuser2 11mo agoThe problem with catch-all inbox is when you have to reply to an email. Then you have to create the email address to be able to send emails from it. Or are there other solutions?
- TZubiri 11mo agoTrue, I simplify it a bit based on the capacity of my mail provider. I have like 4 or 5 generic addresses that I give out and use for sending. Sometimes I mix up when sending, but my mail provider (zoho) is pretty decent at keeping track of the addresses anyways. In a way if I reply, the other party gets upgraded to one of my 5 addresses, so if they send an email to ContosoCoffeeShop@myname.com I might reply from whatever flavour I'm using nowadays or is more appropriate like hello@myname.com It's like a 3 layer security system, the least privileged get access to one very specific address, if they send me an email which makes sense and I reply, they get upgraded to a bucket. I might sign up directly with a bucket email and skip the most paranoid layer, that's fine. In general I try to take more care of the newest alias and become more liberal with my older more ruined addresses, alias1@ has like 8 years of signups, while alias5@ has just 1 if any. And I'm sure the list will grow. Downside is that if there's a leak it's harder to attribute exactly, but at least I can check the recipient to get some kind of hint. It's more like art than it is a water-tight security protocol. You paint the world with your wacky addresses and occasionally surprise the observant employee with the inverted expectations (usually the name comes before the at) Thank you for coming to my ted talk.
- joshka 11mo agoTroy's response [1] on this use case from a couple of years ago was that you should buy a monthly fee and then cancel it. [1]: https://www.troyhunt.com/welcome-to-the-new-have-i-been-pwned-domain-search-subscription-service/#comment-6274826345 https://www.troyhunt.com/welcome-to-the-new-have-i-been-pwne...