10 ms·
There have been enough data breaches at this point that I'm sure all my info has been exposed multiple times (addresses, SSN, telephone number, email, etc). My
by naet 11mo ago
There have been enough data breaches at this point that I'm sure all my info has been exposed multiple times (addresses, SSN, telephone number, email, etc). My email is in over a dozen breaches listed on the been pwned site. I've gotten legal letters about breaches from colleges I applied to, job boards I used, and other places that definitely have a good amount of my past personal information. And that's not even counting the "legal" big data /analytics collected from past social media, Internet browsing, and whatever else.
I now use strong passwords stored in bitwarden to try to at least keep on top of that one piece. I'm sure there are unfortunately random old accounts on services I don't use anymore with compromised passwords out there.
Not really sure what if anything can be done at this point. I wish my info wasn't out there but it is.
- kccqzy 11mo agoAddresses? Most of the time addresses are a matter of public record. I have used https://www.fastpeoplesearch.com/ https://www.fastpeoplesearch.com/ a couple of times to search for people's addresses and it really works. One day a close friend excitedly told me she bought a new house and I told her the address before she told me about it. Telephone number? There used to be phone books. And I still instinctively think they should be public.
- animex 11mo agoI think the headline is a bit vague, it includes passwords as well. Does anyone know if Troy's HIBP'd site reveals the passwords to verified users? I'd like to know if my current or what generation of passwords has been breached to evaluate if I have a current or past problem with my devices.
- birdman3131 11mo agoThey do not want to have such a list as it makes them a target. What they do have is a searchable password list not connected to any usernames.
- NoahZuniga 11mo ago*searchable list of password hashes
- lotsofpulp 11mo agoAddresses can lead you to public land and mortgage records, and phone numbers can lead you to names and addressed. I assume everyone can easily find that out about me once they know my name/phone number.
- Cthulhu_ 11mo agoAn address can be dangerous if it's e.g. a social network site or blog, anywhere where you post under an alias. People make enemies, have stalkers, or say things online that certain regimes don't like. Granted, this is only really a thing for a minority, but if a minority isn't safe, nobody is.
- coleca 11mo agoI was thinking the same thing. Can you imagine the headline? "Forget Hackers! Phone Company Delivers Your Private Info—Including Your Home Address—Directly to Strangers!"
- skinkestek 11mo ago> Telephone number? There used to be phone books. And I still instinctively think they should be public. I used to think the same. Around here I feel until a few years ago most people I knew with secret phones were people I would prefer to have fewer interactions with: people who frequently got into trouble, tried to scam others etc. These days I’m more in the camp of layered security. Whatever I can do to make it harder for an attacker, the better. > I have used https://www.fastpeoplesearch.com/ https://www.fastpeoplesearch.com/ a couple of times to search for people's addresses and it really works. Tangential: Sorry, you have been blocked You are unable to access fastpeoplesearch.com (Safari on a stock iPhone, mobile broadband from the biggest and most well known telecom company in my country, ipv6 address.)
- kccqzy 11mo agoThey probably block non-U.S. IP addresses since it's for persons in the U.S.
- kulahan 11mo agoI was in the military. China stole my freaking DNA profile. I've given up on worrying about this stuff.
- rdl 11mo agoEven better "please give us all the things which could be used by a foreign power to blackmail you, or apply pressure to relatives or other close contacts" and then poorly secure that database.
- smsm42 11mo agoThose are the same guys who told us we must give them backdoor keys to every encryption algorithm, because nothing can go wrong with it and otherwise terrorists win.
- harvey9 11mo agoGonna be a very weird day for you when China's clone army invades us.
- rafabulsing 11mo agoIf nothing else, I guess one should at least be kinda proud that of all stolen DNAs, yours is the one they end up making a clone army out of.
- kulahan 11mo ago5,000,000 Kulahans invading America would not be very effective thus I have defeated China myself, no thanks are necessary.
- WaitWaitWha 11mo agoThe number of years I got "free credit monitoring" I can pass it down to my children . . .
- 11mo ago
- eyeundersand 11mo ago+1 for Bitwarden. It is literally the best solution out there. Been getting to increase uptake in personal circles with (very) limited success. The wife keeps trying to convince me that the ship has sailed in trying to protect info online. She's probably right.
- stronglikedan 11mo ago> Bitwarden Best when paid for so you can do 2FA with TOTP codes!
- troyvit 11mo agoI self-host through Vaultwarden but I think I miss this. Besides, I feel like paying these guys anyway just for the great product. We use 1Password at $dayjob and it's so primitive by comparison.
- shinypants 11mo agoWhat is lacking in 1Password by comparison? I pay for a family plan but maybe I should switch next year.
- troyvit 11mo agoHere are the things that get me, and maybe it's because I haven't configured it well yet. 1. On firefox first start-up is slow after unlocking to actually find a password for a site. The interface says, "No logins for xyz.com" for maybe 5 seconds before the login loads. 2. Along those lines when I open it first thing in FF the box for its password isn't focused and I have to click it. 3. The keyboard combo to open it also only works in Chrome. 4. To add a new login I have to go to the site. I haven't figured out how to do it from within the plugin. 5. We get alerts at least once a week about service disruptions but they don't seem to actually affect me. 6. I like Bitwarden's command line tool but I bet 1Password has something at least as good that I haven't found yet.
- jnrk 11mo ago
- neogodless 11mo agoI use unique email addresses per domain name, and I believe IHaveBeenPwned shows me at 39 unique email addresses breached! (So many that seeing which ones have been breached would now cost me $22 / month... IHaveBeenPwned is starting to feel like an extortion racket of its own..)
- mrbluecoat 11mo agoI feel you. The aggregate email breach list just feels like a rainbow table at this point.
- esnard 11mo agoIf you're using the same domain for each of your email address, HIBP has a domain-wide search feature which is free (but you need to register to validate your domain)
- neogodless 11mo agoI've registered (years and years ago) and I get emails saying how many, but to see which emails they want lots of money. (If I'm wrong their interface is very confusing and I cannot find the free access.) Specifically it says this: > Insufficient subscription. Only subscription-free breaches will be returned for this domain. So I'm able to see 37 email addresses on my domain have been breaches, but I can't see which without paying $22 / month - https://haveibeenpwned.com/Subscription https://haveibeenpwned.com/Subscription > Domain search restricted: You don't have an active subscription so you're limited to searching domains with up to 10 breached addresses (excluding addresses in spam lists). Only results for subscription-free breaches are shown below, upgrade your subscription to run a complete domain search. If you believe you're seeing this message in error, make sure you're signing in to the dashboard with the correct email address (check your latest receipt if you're unsure).
- solarwindy 11mo agoQuoting Troy from a thread beneath the article: > The easiest approach in that case is to take out the subscription, then immediately cancel it. It'll still last the full month, more here: https://support.haveibeenpwned.com/hc/en-au/articles/7707041970703-How-can-I-minimise-the-subscription-cost-of-domain-searches https://support.haveibeenpwned.com/hc/en-au/articles/7707041...
- Razengan 11mo agoSo by this point, if anyone does anything naughty online they could just pin it on an hacker using their identity, no?
- TZubiri 11mo agoRight. Having some data leaked isn't really a boolean, leaked/unleaked. It's a list of leaks, and the implicit map betweenyl your datapoints, whether by intra or interprovider mapping For example a forum might leak a map between your mail and a password; Implicitly your affinity for that forum's topic is also now on the public record, additionally if your posts were public but under a pseudonym, that might be now known by a sufficiently motivated attacker. Finally this may be linked with other public datasources like your public tweets or public state records, or even other leaks. This is why the meme about all ssn's being leaked or about a list of all valid phone numbers is so asinine.
- sixothree 11mo agoEven if you weren't breached, the sophistication is getting higher too. New hires get emails starting literally day one because email formats follow a pattern and they posted their new job on linkedin (or something).
- NegativeLatency 11mo ago> what if anything can be done at this point I'm in a similar situation, just make sure your credit is frozen with the 3 major US companies. I had someone steal like $50 of cable TV with my info in another state and it was a major pain to get off of my credit report.
- dheera 11mo agoI generally don't give my real address or real phone number to anyone who doesn't legally need it. I use a virtual address as the billing address on my credit cards and for registering for things that don't need to know where I sleep. The government can have at my real info, but private companies have bad data security.
- s5300 11mo ago[dead]
- 8cvor6j844qw_d6 11mo agoI used per-account email with alias services and password managers. Also started migrating old accounts in free time. Now its pretty easy to tell the source of leak by email addresses as well as sources of spam. --- Per-account alias might sound much, but using sieve filtering [1] is amazing, and you can get a comprehensive filtering solution going with 'envelope to' (the actual address receiving the email) + 'header to' (the recipient address you see, sometimes filtering rules don't filter for BCC or sometimes recipients are alias instead of your actual email) that are more comprehensive than normal filtering rules to sort your emails into folders. [1]: https://datatracker.ietf.org/doc/html/rfc5228 https://datatracker.ietf.org/doc/html/rfc5228 --- Amusingly, I've managed to recover old accounts from emails that contains my old passwords with demands for crypto payment, it just provided me enough help to recall old variations of my passwords.
- lelandfe 11mo ago(the keyboard smash username is apropos) > Per-account alias might sound much Not only does this not sound too much, this is a feature Apple offers called Hide My Email: https://support.apple.com/en-us/102548 https://support.apple.com/en-us/102548
- fainpul 11mo agoAnd one day you've had it with Apple's latest user-hostile shenanigans and switch to Linux. What now? Do you just keep paying for iCloud+ forever?
- marliechiller 11mo agowouldnt this be the case for any vendor you choose?
- fainpul 11mo agoyes
- vladvasiliu 11mo ago
- varispeed 11mo agoI bet now some corporations actually want to be exposed, have data breach. If you have not been in the news, it means you have not made it yet (not popular enough to be a target worth writing about).
- esseph 11mo agoThose CISOs / CTOs / CIOs attached to those companies do not want to be in the news.
- edoceo 11mo agoRight to be removed/purged and maximum retention policy. One place I'm aware of purges accounts that have been inactive 18month. Historical billing info is offline and "gapped"
- sandeepkd 11mo agoTo confirm, data/info leaks happened on the server/application side. How does a solution like Bitwarden on the client side helps with this situation? As per my understanding the only possible threat it saves against is someone trying to brute force for your password against the application. And may be ease the cognitive burden of remembering different passwords.
- theonething 11mo agofreeze your credit at the three major companaies.
- ulfw 11mo agoExactly this. Does anyone still care? I like how the Apple Password app informs you about Compromised Passwords so you can you know... go in and fix it, get a new password etc. Nice little cute idea. I got 717 warnings. Seven hundred seven teen. No I will never be able to fix this
- ErroneousBosh 11mo agoIt's probably more important to keep passwords safe, but lots of people treat their email address like some kind of "sensitive secret". "Oh but I don't want to get spam" - my dude you are going to get spam. There's a guy who lives near me who, when he parks his car, very carefully puts tape over the number plate "because otherwise people might see my registration number". Because apparently if people can see your car's registration number they can somehow just steal your car and the police won't do anything because the number plate was visible. Mad, absolutely barking mad.
- TacticalCoder 11mo ago[dead]
- somehnguy 11mo agoSame, and I find it really difficult to care about it anymore. It was leaked through no fault of my own. There are 0 actual consequences to companies doing it. So what am I going to do - stew about it??