8 ms·
1k Data Breaches Later, the Disclosure Lag Is Worse
- charcircuit 4mo ago>why is it still needed? It's not needed. There are already alternatives that could take its place. Some of them are able to actually show you what data leaked instead of leaving you blind of what was actually included in the breach.
- ozyschmozy 4mo agoCan you give examples of these alternatives?
- parable 4mo agoI use Snusbase (https://snusbase.com https://snusbase.com). They've been around since around 2016 and haven't had any issues legally - they're the longest-standing data breach search engine besides HIBP, as far as I know. (This is not an advertisement.)
- J-Kuhn 4mo agoThis is a bad idea, for multiple reasons. https://www.troyhunt.com/here-are-all-the-reasons-i-dont-make-passwords-available-via-have-i-been-pwned/ https://www.troyhunt.com/here-are-all-the-reasons-i-dont-mak...
- khafra 4mo agoI don't think he meant "show the actual data," I think he meant "what leaked? My name, address, phone number, email, medical records, payment history, bank account number?" We get a "your private data is now public" email, but knowing exactly what data turns that from a depressing statement on how much corporations value their customers' privacy into something actionable.
- J-Kuhn 4mo agoThis information is shown on the site of the breach, as example: https://haveibeenpwned.com/Breach/BakerDistributing https://haveibeenpwned.com/Breach/BakerDistributing
- charcircuit 4mo agoYes, I meant the actual data so you know what leaked. There is a difference between leaking a password 12345678 and leaking a password that was reused on a different site. There is a difference between leaking your actual birthday and leaking 01/01/1900. There is a difference between leaking a fake address, your previous address, and your current address.
- pixl97 4mo agoThen feel free to browse the onion and buy data that you may be included in. There seems to be some amount of entitlement by people in this thread to get information from a third party about what a first party to them lost. The first party that lost your data should be the one that shows you exactly what was compromised.
- charcircuit 4mo ago>Most breaches already contain hashed passwords It could show the hash instead. >No, it's not ok that these passwords are already out there So it's better that people have to pay for it instead of getting this information for free? >Because it's important to say "I don't store passwords in HIBP" This is a personal choice. >I'm not your personal lookup service The idea is that this would be done by the site itself and would not require manual work by the owner.
- parable 4mo agoHashes can be cracked, and end users won't understand how to create password hashes to check which one was leaked. Plus, salts exist. Passwords shouldn't matter anyways. Use a password manager and be done with it. The real issue is metadata which can't easily be changed - phone numbers, addresses, and the like. If any of that data is leaked, it becomes much harder to contain impact. You can't move addresses every time your address gets leaked online.
- zx8080 4mo agoIs there ANY business motivation for any corporation to open such information up sooner than later?
- GaProgMan 4mo agoDepends where they are in the world. I _think_ GDPR would be a good enough business reason, as they set a ticking clock of 72 hours from the breach to notifying individuals who are in the breach. And the fines involved are pretty steep (almost effing vertical for some).
- c0balt 4mo agoA minor problem with GDPR is enforcement. At least in germany it feels like you need a very dedicated and persistent person to make the case against a company/service (bonus points if they get media attention). Other countries are a bit better but it generally is not very consistent. The enforcement for most small to mid-sized companies is often just not present and resources for relevant agencies are often only reluctantly allocated. Ime, in government institutions it is generally not very respected as it "impedes progress".
- visha1v 4mo ago[dead]
- bcye 4mo agoAt least there is the very dedicated and persistent https://noyb.eu https://noyb.eu :)
- trumpdong 4mo agoSee how many of their cases have been dragging on since almost the beginning of GDPR.
- hn773746483 4mo agoNOYB has been ghosting me since January, and EFF since September.
- faangguyindia 4mo agothere will be more data breaches. Google and Apple are throttling hotfix updates (for app developers) as tons of code pushes to their infra (by vibe coders) is straining their system. The are fixing this by throttling updates to minimum 3 days review period. so good luck fixing the vulnerability or data leaks in your apps.
- HDBaseT 4mo agoI am not sure I get the connection between AI code holding up review processes and data breaches.
- emodendroket 4mo agoThe post made a pretty clear claim, I thought: the volume of apps being sent through is so extreme that they can't keep up with their review process.
- ai_fry_ur_brain 4mo agoDont worry the vibecoders will tire out, they're the same people who were making NFTs and mining bitcoin, they'll move onto the next hot thing soon enough. Its more an archetype, not necessarily the same exact people. They dont commit long term.
- glemmaPaul 4mo agoThis indeed. They are the "type of guy type of guys", always drifting to next big thing® I wonder whats next, I feel it might be a huge swing of the pendulum next.
- pixl97 4mo ago>Dont worry the vibecoders will tire out This seems to rhyme with "Don't worry, the spammers will tire out" Narrator: "The spammers in fact, did not tire out"
- parliament32 4mo ago
- deleted 4mo ago[deleted]
- keyle 4mo agoAt this stage just expect that every accounts will get leaked or rooted, it's a matter of when, not if... Use varying email `plus addressing` (john+am2604@foo.com), varying passwords or passkey and 2FA on anything remotely important (use of your identity, not just financials).
- deleted 4mo ago[deleted]
- andrepd 4mo agoThe + trick is useless to protect you, obviously. Instead, use a a service like simplelogin to create unique emails for every place you sign in.
- Cider9986 4mo agoI recommend people use proper email aliasing, not plus addressing. Duckduckgo makes a free one that's can integrate into Bitwarden, if you have iCloud+ Apple's($0.99/month) hide my email is good. Addy.io and SimpleLogin are the best and allow PGP encryption to prevent another party having access to your emails, but they are paid for full features. > Organizations like the IAB require that advertisers normalize email addresses so that they can be correlated and tracked, regardless of users' privacy wishes. https://www.privacyguides.org/en/email-aliasing/#over-plus-addressing https://www.privacyguides.org/en/email-aliasing/#over-plus-a...
- IshKebab 4mo agoPlus addressing doesn't work well unfortunately - lots of poorly written websites will reject it.
- kleiba2 4mo agoFor years, I've been trying my best to stay low-key when it comes to my personal information on the internet. I don't create new accounts, I never cross-login with my email address, I don't use phones. Certainly not perfect, but a lot of times I'm preferring privacy over convenience. At the same time, my government and society at large is pushing more and more for "digital everything". It's great when it works. But to me, every new service translates to a new opportunity for my data to be leaked. I think one reason why we're still seeing so many breaches is that security is hard and thus expensive - and on the other hand, other than customer push-back, companies or other providers have pretty much nothing to worry about when their data gets extorted. To me, this is impossible. When I give my private data to them, I'm giving them something very valuable. If being careless with that value basically has no consequences, the incentives to care are low. We need to establish measures of accountability for data holders. Not securing customer data appropriately needs to be persecutable, and the affected parties need to be given a right for compensation. Of course, that's not going to happen. It would be difficult to implement in practice, if at all possible. But as long as there is no monetary incentive for data holders to be as careful as possible, the laxness is going to continue.
- awesan 4mo agoIf a business legitimately needs such information to operate, isn't it borderline impossible to 100% prevent it from leaking? If the data is there, it can be compromised either by technical means or non-technical means. The primary issues in my opinion are (1) businesses collecting and holding on to information they don't need and (2) businesses getting so large that they become prime targets by default. In a world where pointless data collection was disincentivized and there were many small businesses instead of a few large ones, this problem would be much more localized and addressable. But of course this is a dream within a dream.
- parable 4mo agoI'd also add a third issue to this list: data retention. Too many companies I've dealt with have privacy policies that state something to the tune of "we'll hold onto your data for as long as required" without giving much of an explanation as to how long "as required" is.
- steveharing1 4mo ago[dead]
- ian_holt 4mo agoI found I had exactly that issue ~3 months ago. A particular government department had their systems hacked and 1 of my email addresses became public along with 10s of thousands of other users. That in itself was bad enough except that this particular department had known about the breach about 2 months earlier and to make matters worse they had not been aware that the breach had occurred back in June 2025. <We need to establish measures of accountability for data holders. Not securing customer data appropriately needs to be prosecutable, and the affected parties need to be given a right for compensation> I 100% agree with you here. The trouble is, the government which are often the ones to push for major court-issued penalties when corporations stuff up, don't want to be held to the same level of scrutiny and penalty. Go figure
- ItsBob 4mo agoThese days I treat other people's data like it's a live hand grenade. Case in point (bit of a shameless plug here :) I'm working on an App called Hockeytastic. It's an ice-hockey stickhandling app that my son's been using for months: the engine is solid but it looked like shit. However, his coach told me to get it on the app stores and sell subs. That meant I needed to clean it up, build a DB, store stuff etc. Anyway, working with Google and Apple I realised that I quite literally do not need to store anything identifiable. The only identifier I store is the Apple id and the Google id and unless you steal those and then hack Google and Apple, they are utterly useless. I do not store emails, names, addresses, nothing. That's the way I want it. If the data is ever breached, the only thing hackers will see are many many instances of Connor McDavid, Nate Mckinnon and various other famous NHL player names :) If more companies treated personal data like it was toxic, we'd have less issues with breaches, however, I see it in my day job where the marketing people want to take as much data as possible, all the time!
- parable 4mo agoI wish that were the case, but because of there being barely any consequences for breaches, it's much more profitable to store everything you can and sell it to the highest bidder. Make it a huge risk to store data, then companies will start treating data like a live hand grenade.
- wongarsu 4mo agoThat's exactly what the GDPR tried. If only it was properly enforced
- parable 4mo agoCompanies can and do get away with arguing that they have a "lawful basis" to collect whatever data they'd like. It's unfortunate. IANAL, but the law seems a bit vague to me, and it appears that companies use that vagueness to their advantage. Maybe I'm just not articulating my arguments correctly.
- 4mo ago
- axegon_ 4mo agoNot to spoil the surprise but it will get much MUCH worse. Reason: sloppers. Anyone who's dealt with security and has looked into how all the slop agents work can understand how catastrophic it is from a security perspective. The "yes" button on "I trust the authors" is what unlocks the gates of hell.
- ripharamberip 4mo agoI have a custom domain for my emails with catch all. When I create an account somewhere I just use <name of the service>@my-domain.com Can I find out if any of my emails are in leaks with a service somewhere?
- kitd 4mo agoThat's literally what Have I Been Pwned is for. https://haveibeenpwned.com/ https://haveibeenpwned.com/
- Perz1val 4mo agoOne by one, but I think the question is about the entire domain name
- Brajeshwar 4mo agoYou can have haveibeenpwned.com check for the custom domain itself. For instance, I get notified if any email of our family domain get leaked (not just mine).
- wongarsu 4mo agoIf you sign in that's an option on your dashboard. You need an account because you need to verify the domain is yours
- stevekemp 4mo agoYes, but note that you have to pay for that, see the pricing here: https://haveibeenpwned.com/Subscription#corePlans https://haveibeenpwned.com/Subscription#corePlans For me, with a similar wildcard setup, it became something I wasn't willing to spend money on. I work on the basis that accounts are compromised and if the company is large enough I'll see it in the news. Strong passwords, and a password-database is the best I can manage.
- lionkor 4mo agoYou don't, you can register a whole domain and it'll work.
- ChrisMarshallNY 4mo agoAs usual, the answer is never "collect less data." That's the only sensible approach. It's the one that I use, but then, I care about the users of my software, and I don't make any money from their PII.
- cfiggers 4mo agoSo at the risk of sounding incredibly apathetic toward something that I'm sure is probably a massive headache for some people somewhere... I'm a millennial and I've been told probably hundreds of times by this point in my life that my data has been breached. Not a single one of those times was there a) anything truly actionable for me to do about it[0] or b) a single negative impact to my actual life. In anyway. At all. People were talking about the Equifax breach a decade ago like identity theft was going to become an absolutely routine part of daily life for +90% of people. That didn't happen, at least not for me. My point is: I understand that this is a topic that nerd communities like HN are well-aligned on—data collection bad, data breach bad, I get it. But does it actually matter? Every single one of us have had our data harvested by tech giants every second of every day for absolutely decades and neither I nor a single person I know in real life have ever had any negative consequences, either because of the collection itself or from the inevitable and seemingly continuous breaching of that data. Every single website, from the random indie shoe website I purchased from one time to multiple health insurance companies, have breached my data, over the span of decades, and from all appearances it has had absolutely zero effect that I can actually point to in real actual life. So I'm becoming a bit of a skeptic on this item of quasi-religious dogma that y'all all seem to recite the same position on. Does the emperor perhaps have no clothes? Do we all just fear "data breaches" because we've been told to fear them by people who sounded smarter than us? I need y'all to hit me with some scary anecdata about what happened to your hairdresser's cousin's ex-husband's dog—anecdata with no citation that I obviously can't even verify isn't hallucinated by a GPT, but should clearly accept as valid because "ooooh data breach bad"—because without that the propaganda patina on my brain is wearing a little thin. [0] (I use a password manager to guarantee that I'm not sharing passwords between logins, so really the only thing I could do in response to a data breach disclosure is rotate the password on the breached account. But that only matters if they were storing my password in plaintext right? I certainly can't do anything about my data being out there, and it's too late for closing that account out to prevent anything.)
- BoxFour 4mo agoI feel you're correct, and it's why it's a losing battle. It's a spectrum of consequences. The worst outcomes are serious but rare. For most people the most severe outcome they'll deal with are unauthorized credit card charges, which are an annoyance at worst. The most severe consequences just aren't common enough to elicit any kind of change, and even when they are the response is about cleaning up the damage instead of fixing the upstream problem (how that fraud was allowed to occur in the first place).
- 1vuio0pswjnm7 4mo ago"Today, I loaded the 1,000th data breach into Have I Been Pwned. Reflecting on that milestone number, I pondered how to mark the occasion in writing, and what immediately came to mind was a very simple question: why is it still needed?" Maybe it isn't needed Originally HIBP and other websites used data breach dumps to solicit further data collection^1, e.g., with a fear-based, clickbaity title like "Have I been pwned?" Maybe HIBP serves the author, maybe that's why it's "needed" For example, it brings him notoriety For example, he can promote his other cybersecurity website via HIBP and paid speaking engagements The author has expressed dissatisfaction that companies are being penalised for data breaches through class action litigation, including any compensation users might receive as part of these settlements He believes there is no user injury https://www.troyhunt.com/data-breaches-class-actions-and-ambulance-chasing/ https://www.troyhunt.com/data-breaches-class-actions-and-amb... If that's his position, if he believes users are unharmed by data breaches, then what's the point of HIBP Is it to support the companies who are collecting data and then being breached (not the users to whom the data belongs) 1. Data collection being the root cause of the data breach problem
- BoppreH 4mo ago1. People come to him with breaches that are not public yet. 2. He validates the breaches through a network of volunteers who check if the credentials are real. 3. He provides an easy-to-use service for free. What is your alternative? Having each person run their own agent scanning the corners of the internet, downloading breaches, and looking for their own accounts? What the point of that?
- Veserv 4mo agoA problem of incentives. How can we fix it? Advertising tied to liquidated damages. 1. Any company handling PII must prominently advertise a amount of money per user they must pay in cash in the event of a data breach. This is a mandatory minimum payment and does not preclude subsequent lawsuits on specific damages. 2. Any claim of security or privacy must prominently advertise that amount earlier and in larger text than any other statement: “We provide 25 cents of security.” 3. In the event of data breach, your first notification must inform all affected partys and you immediately become tentatively liable for your data breach amount. Any affected party not notified in the initial disclosure receives 3x damages in the event their data was lost. 4. You may disclose to partys that you now know they are not affected. In the event that their data was lost they will receive 3x damages. 5. In the event of a data breach, you must issue your first notification within 1-7 days of when you discover it or are informed of it. Failure to do so constitutes a first notification to 0 partys, so you become liable for 3x damages to all users. 6. A data breach of any vendor you supplied PII to constitutes a breach. 1 and 2 align marketing with capability. 3 and 4 prevent underreporting. 5 prevents late reporting. 6 prevents diffusion of responsibility or the creation of scapegoat entitys and incentivizes only using vendors who properly track data provenance so their lawyers can tell your lawyers your users are unaffected.
- mujahidmughal2 4mo ago[flagged]
- mujahidmughal2 4mo ago[dead]
- mujahidmughal2 4mo ago[dead]
- usamaansari2 4mo ago[flagged]
- WildSense 4mo ago[flagged]
- Scarlett5 4mo ago[flagged]
- WildSense 4mo agoI've tried using headless browsers with geolocation API overrides, but they don't always match real-world results. Your tool seems more practical—does it handle mobile vs. desktop differences for local searches?