5 ms·
I respect Troy Hunt's work. I searched for my email address on https://haveibeenpwned.com/ https://haveibeenpwned.com/, and my email was in the latest breach da
by jimmar 11mo ago
I respect Troy Hunt's work. I searched for my email address on https://haveibeenpwned.com/ https://haveibeenpwned.com/, and my email was in the latest breach data set. But the site does not give me any way to take action. haveibeenpwned knows what passwords were breached, the people who breached the data knows what passwords were breached, but there does not seem to be any way for _me_, the person affected, to know what password were breached. The takeaway message is basically, "Yeah, you're at risk. Use good password practices."
There is no perfect solution. Obviously, we don't want to give everybody an easy form where you can enter an email address and see all of the password it found. But I'm not going to reset 500+ password because one of them might have been compromised. It seems like we must rely on our password managers (BitWarden, 1Password, Chrome's built-in manager, etc.) to tell us if individual passwords have been compromised.
- junon 11mo agohttps://haveibeenpwned.com/Passwords https://haveibeenpwned.com/Passwords
- ekjhgkejhgk 11mo ago[flagged]
- jolmg 11mo ago> Passwords are protected with an anonymity model, so we never see them (it's processed in the browser itself), but if you're wary, just check old ones you may suspect. That could mean one might be able to disconnect from the internet while checking.
- ekjhgkejhgk 11mo agoNo, it doesn't mean that, that's ridiculous. How would that work? Magic?
- deleted 11mo ago[deleted]
- bobmcnamara 11mo agoDownload all the hashes first - not practical.
- zahlman 11mo agoThe above post https://news.ycombinator.com/item?id=45840724 https://news.ycombinator.com/item?id=45840724 links to 71.3 KiB of data; since it's a 5-nybble prefix (20 bits) we may easily estimate a size of 71.3 GiB assuming that's a representative sample. Not unfeasible nowadays, but it seems you do have to make separate requests and would presumably be rate-limited on them. If you only download the hash pages corresponding to passwords you hold, even supposing that everything else is fully compromised, an attacker would have to reverse a couple thousand SHA-1 hashes, dodge hash collisions, and brute-force with the results (yes, yes: arson, murder and jaywalking) to pwn you.
- WorldMaker 11mo agoIt's more practical than you may think. Just needs about 40 GBs right now. I did it a couple years back in a fit of peculiar paranoia, downloaded the full hash list and checked all my KeePass-stored passwords at that time against it. https://github.com/HaveIBeenPwned/PwnedPasswordsDownloader https://github.com/HaveIBeenPwned/PwnedPasswordsDownloader
- sunaookami 11mo agoHaveIBeenPwned has been around for ages and it does not send your password to the server - you can check it with the browser console. It hashes it, sends a range of the hash to the server, server replies with a list of hashes that match that range and it's checked locally for a match.
- smokel 11mo agoStill, I would not trust that. The password could be leaked through other means, for example by setting a timer, and exfiltrating fragments of it across future requests. The website loads some external fonts and spits out many warnings in the console by default. Does not instill confidence in the truly paranoid hacker.
- turnsout 11mo agoYou can check it yourself by looking up the hash prefix and searching for your hashed password.
- TZubiri 11mo agoThat level of care is warranted, but you'll find that you are given the tools to audit and it will pass.
- drexlspivey 11mo agoYou can hash yourself and check against the api with 5 lines of python
- bobmcnamara 11mo agoMan, there's a ton of non-obvious ways they could exfiltrate that. I'm not going to read their code.
- MattSteelblade 11mo agoYou can check against the API with just the first characters of your hashed password (SHA-1 or NTLM), for example: https://api.pwnedpasswords.com/range/21BD1 https://api.pwnedpasswords.com/range/21BD1 or you can download the entire dataset.
- zahlman 11mo agoSecond line I already notice: > 000F6468C6E4D09C0C239A4C2769501B3DD:5894 ... Does the 5894 mean what I think it does?
- esnard 11mo ago5894 means that the password appeared 5894 times in the dataset. 5894 is not the password associated with the hash.
- red369 11mo agoI remember when I was searching the file for some passwords my friends and family use, it took me a while to work out that number too. There are some passwords that many people seem to independently come up with and think must be reasonably secure. I suppose they are to the most basic of attacks.
- ekjhgkejhgk 11mo agoHow can you download the entire dataset?
- red369 11mo agoI was going to provide my passwords to any random person on the internet, Troy Hunt might be close to the top of the list, but I think your sentiment is sensible. I remember searching the dataset being fairly straight forward. It's been a while since I've done it, but I think I just downloaded the text file and then grepped it for hashes of my passwords, but I see people doing much more useful things: https://medium.com/analytics-vidhya/creating-a-local-version-of-the-haveibeenpwned-password-database-with-python-and-sqlite-918a7b6a238a https://medium.com/analytics-vidhya/creating-a-local-version...
- Thorrez 11mo agoYou can download all the hashes and check against them locally. https://github.com/HaveIBeenPwned/PwnedPasswordsDownloader https://github.com/HaveIBeenPwned/PwnedPasswordsDownloader
- AlienRobot 11mo agomy password: 2,408 password: 46,628,605 your password: 609 good password: 22 long password: 2 secure password: 317 safe password: 29 bad password: 86 this password sucks: 1 i hate this website: 16 username: 83,569 my username: 4 your username: 1 let me login: 0 admin: 41,072,830 abcdef: 873,564 abcdef1: 147,103 abcdef!: 4,109 abcdef1!: 1,401 123456: 179,863,340 hunter2: 50,474 correct horse battery staple: 384 Correct Horse Battery Staple: 19 to be or not to be: 709 all your base are belong to us: 1
- zahlman 11mo ago> all your base are belong to us: 1 Only 1, really?
- Sohcahtoa82 11mo agoBecause of the spaces. Without spaces, it's 681.
- e12e 11mo agoPassword2020: 109,729 Edit: louvre: 7,219
- latexr 11mo agoSpaces are skewing the numbers lower. Remove them from any of those and see the number increase at least an order of magnitude. That “let me login” goes from 0 to 4,714 just by removing spaces (“letmelogin”).
- AlienRobot 11mo agoI guess this means passwords with spaces are safer!
- neogodless 11mo agocorrecthorsebatterystaple (no spaces) 4,163
- bdcravens 11mo agoI was trying random phrases just out of curiosity, and couldn't help but chuckle when it said "epsteinfiles" wasn't found :-)
- the8472 11mo agoThis doesn't help. If the email address check says the address has been exposed it doesn't tell you which password that was used together with that has been exposed. Was it one from 10 years ago you don't even remember? Or that's still actively in use? Which one of my hundreds of passwords?
- Thorrez 11mo agoYou can use the API to check all of your passwords. Then you'll know the security state of all of your passwords. https://haveibeenpwned.com/API/v3 https://haveibeenpwned.com/API/v3
- the8472 11mo agoDoesn't help. Some accounts are old and may not be in my current PW DB. Or they were memorized, or forgotten. If the thing suggests the EMAIL (+ associated password) has been compromised for some unknown account then to do a risk assessment I would have find which account it belongs to, not which currently-in-use passwords match the same datasets. Those are different queries, providing different bits of information.
- Thorrez 11mo agoHere's what I'm suggesting: query all your current passwords against the password API. Then you'll know which of your current password are compromised. Change them. You don't need to query old passwords, only current passwords. If you're talking about accounts that you've forgotten the password to: then do you care about those accounts? If yes, probably best to do a password reset and set a new password. If you don't care about the account, then why bother? As for why HIBP doesn't provide an API linking passwords to emails: HIBP has no database that links passwords and emails. So they can't provide any way to query that. They don't want to be in the business of linking passwords to emails.
- ekjhgkejhgk 11mo agoOf course it helps. How's this for making it actionable: Regardless of whether or not someone can associate it with your email, if your password has been seen in the wild, change it. There you go.
- elzbardico 11mo ago> It seems like we must rely on our password managers (BitWarden, 1Password, Chrome's built-in manager, etc.) to tell us if individual passwords have been compromised. Yes.
- karencarits 11mo agoOne possible solution could be to give you an option to send the affected password as a list to the mail address you specify, then only people with access to that mail address will see them
- bobmcnamara 11mo agoHash of the affected password? People share these things and don't always run their own mail servers.
- elwebmaster 11mo agoThat would be a great idea!
- technion 11mo agoAt one point I responded to a haveibeenpwned notice by immediately having the user reset a password. I've got over 200 users in a domain search (edit: for this particular incident), and nearly all of them were in previous credential breaches that were probably stuffed into this one. I'm not going to put them through a forced annoyance given how likely it is the breached password is not their current one, and I'm urging people to start moving in this direction unless you obtain a more concrete piece of advice.
- kbrkbr 11mo agoSame here: reset on first beach (ROFB), but on subsequent ones only if it is no collection, eg a new infostealer breach.
- fckgw 11mo agoThe problem with breaches like the latest data set is that there's no source on where the breach came from, it's an aggregate from multiple breaches. They can't tell you that info because it's not in the initial data set.
- chinathrow 11mo agoYeah and I am confused by his new setup private vs business. I got that mail too but can simply not see what addresses were affected by that breach.
- craftkiller 11mo ago> there does not seem to be any way for _me_, the person affected, to know what password were breached You should be using a unique randomly-generated password for each website. That way, one breach doesn't lead to multiple accounts getting hijacked AND you'll know which passwords were breached solely based on the website list. The only passwords I still keep in my head are: 1. The password to my password manager 2. The password to my gmail account 3. The passwords for my full disk encryption All of those passwords are unique and not used anywhere else. Everything else is in my password manager with a unique randomly generated password for each account. And for extra protection, I enable 2fa on any site that supports u2f/webauthn. I used to reuse the same password for everything, and that lead to a pretty miserable month where suddenly ALL of my accounts were compromised. I'd log in to one account and see pizzas I never ordered. Then I'd open uber and see a ride actively in-progress on the other side of the country. It was not fun.
- taftster 11mo agoYes! Me too. Not adding anything here except a confirmation on the above approach. You kind of need your email password as a "break glass" scenario. But mostly, you just need your password manager.
- DaSHacka 11mo agoand root disk encryption, unless you have some alternative method set up.
- imp0cat 11mo agoThat's the default in this day and age, no?
- taftster 11mo agoI mean, probably should be. But for me, no. Well, not my personal computer anyway. That's a mistake, I know. But corporate computer yes. So no, I don't think "in this day and age" necessarily. And I believe that the vast majority of "normal" users don't do full drive encryption either. But yes, we should.
- TZubiri 11mo agoWhat? You expect the guy to tell you your password? Lol, lmao even. I know roughly what passwords were exposed because either I remember it, or the date of the leak or the associated email. I know simple passwords are almost public and that leaks of say linkedin will be properly hashed, while a vb forum from 2006 might not be.
- pessimizer 11mo ago> But the site does not give me any way to take action. It gives you as much information as you should be given. Any more information would just be spreading around the hacked dataset. It does give you an awful lot of information about the specific hacks that exposed your information, and what was the content of that exposure. You may have been owned, but the way you were owned doesn't really matter e.g. I don't care that my firstname.lastname@gmail.com was exposed as being me. I may not care that my username@yahoo.com account was exposed as being username at archive.org. If that's it, I can keep using them. But a lot of hacks are a lot worse, and you might have to rearrange things or close them down. haveibeenpwned gives you enough information to make all those decisions. Also, your second paragraph seems to imply that the site doesn't tell you if passwords were compromised for an email address. It definitely does by identifying the hack and describing its extent. You don't need the actual password to know that you need to change it. Likely, the hacked site forced you to change it anyway.
- froddd 11mo agoChange the password for what account though? The dashboard doesn’t seem to list the actual website(s ) linked to the email/password breached, so how am I to know which password to rotate? If I follow the recommended best practice, I have a different password for every website or service. That could be hundreds of them. Am I supposed to rotate all of them every time there’s a breach?
- seb1204 11mo agoYou buy you email in and then the result it a website that got breached. Together this should give you enough information.
- the8472 11mo ago> It does give you an awful lot of information about the specific hacks No it doesn't. Enter <old email address> → 5 data breaches → first one says: > During 2025, the threat-intelligence firm Synthient aggregated 2 billion unique email addresses disclosed in credential-stuffing lists found across multiple malicious internet sources It doesn't tell me which site or which of the many passwords used together with that address. Just that it has been in a generic data dump.
- NetMageSCW 11mo agoIf you read the instructions, you will discover https://haveibeenpwned.com/Passwords https://haveibeenpwned.com/Passwords which will let you enter a password and securely check if it has been published in a breach. If it has, it is either a simple password that multiple people are using, or a complex secure password that can make you pretty confident it is your password that has been published. 1Password just does the same thing for all of your passwords - it doesn’t check against your account name either. That information isn’t stored so they can’t become a new source of breached accounts (as explained at the site).
- donatj 11mo agoLetting me check my passwords one at a time is like letting me check my grains of rice individually for poison before eating.
- jve 11mo agoUse a tool https://monitor.mozilla.org/ https://monitor.mozilla.org/ https://watchtower.1password.com/ https://watchtower.1password.com/ https://bitwarden.com/help/reports/#exposed-passwords-report https://bitwarden.com/help/reports/#exposed-passwords-report
- Jaxan 11mo agoThere is also an API
- froddd 11mo agoThe details about the “Stealer Logs” on the dashboard even state: > The websites the stealer logs were captured against are searchable via the HIBP dashboard. There is no way to use the HIBP dashboard to figure out what domains my email address appears against. Am I meant to change all passwords associated with that email address? Or do I need to get a paid subscription to query the API to figure out exactly what password(s) to change? This has always confused me. On the one hand, HIBP is an invaluable service, but, on the other, it does nothing more than stating you’re in trouble, with no clear way forward.
- subscribed 11mo agoIt's quite certainly a up selling attempt. I once spend a couple of hours to see what was actually exposed in the infostealer breach my email appeared (eg: payment data? Physical address? Government id ?) to no avail. This service is toxic tbh.
- Thorrez 11mo agoThe API is free. https://haveibeenpwned.com/API/v3 https://haveibeenpwned.com/API/v3
- subscribed 11mo agoRespectfully, in context of my claim (that this is upselling attempt), your answer is untrue. "You need an active subscription in order to provision an API key". This is minimum $4.50 pm. Of course it's not a lot but let's not move the goalposts by discussing whether it's a fair price or not. I don't want to say it's a lie, because I assume you didn't know. API is a paid service, not free. Separately, if I open the dashboard link while being logged out, the Web page promises: "viewing stealer log entries that captured your email address" Needless to say, this is also false (maybe true with a paid subscription?). If I click on the Stealer Logs in the dashboard it only shows "discord.com" (old account I used with this email was deleted years ago), and nothing else. Even though Breaches suggests there's something else. This is not "logs" by any stretch of imagination.
- 11mo ago