5 ms·
Have I been pwned? Check if you have an account that has been compromised
- sordidfellow 12y agoI don't know about you, but I can't bring myself to punch my ID into a random website.
- drivingmenuts 12y agoI feel like I will have been pwnd. Maybe that's the next website to build: willihavebeenpwnd.com and then whenwillibepwnd.com
- jgeorge 12y agoIt's time to break out Dr. Dan Streetmentioner's new Guide to Future Domain Names.
- mseebach 12y agoUnless you use different usernames/email addresses for all the websites you sign up for, this website isn't any more or less random than any of the hundreds of websites you've punched your ID into (and of which some, more likely than not, has been compromised).
- sprash 12y agoIf you fear your credit card info has been stolen, enter it here and you can find out for free. Avoiding fraud has never been easier!
- kazinator 12y agoNot the same thing at all because your e-mail address isn't a security token. e-mail addresses aren't secret; you give them away all the time. Would you put your credit card info on a business card and give it to people you meet?
- gizmo686 12y ago>Would you put your credit card info on a business card and give it to people you meet? Of course not, I just hand it to the minimum wage cashier, say it over the phone whenever I am ordering delivery, and type it into online stores.
- rwallace 12y agoIt only asks for your e-mail address, not your password or any other secret information.
- kevinoconnor7 12y agoThey should really accept a hash of your email/username to lookup. Then we can an idea of if we've been pwned without giving additional information if we haven't been.
- jdludlow 12y agoI'm not sure how that would help. They would have to generate a matching hash on their end, giving them a lookup table to work backwards from hash to email address. Now if they wanted to supply a list of hashes to the public, then you could check your own without knowing any of the other addresses used to generate the remaining hashes.
- kevinoconnor7 12y agoYes, but they would already have your e-mail address anyway. Lookup by hash precludes the case where you're giving them information they didn't already have.
- bitJericho 12y agoBut you're still feeding into the "this is a good working address" and "this is a security newb" email lists.
- jdludlow 12y agoTrue. I was more referring to it being a confirmation that this is an email address that anyone cares about. If I wanted to be truly malicious I'd have my online checker return a "Nope, you're all good" and then add that email address to the short list of accounts to go after.
- wglb 12y agoBut the point is that your email is possibly already out there, circulating around. Would you rather not know?
- superuser2 12y agoThe fact that your username exists is almost always public information, and all you'd be disclosing. That's why we have passwords.
- WhatsName 12y agoAnyone here, who can say whether this service is trustworthy and not collecting additional Email addresses?
- gk1 12y agoApparently it's made by this person: http://www.troyhunt.com/ http://www.troyhunt.com/ Doesn't raise any red flags for me. As someone else pointed out, it's trivial for someone to collect emails or find your email. Heck, this latest dump has 5 million of them...
- jqueryin 12y agoAgreed that he's legit and I can also verify it works as expected. It notified me of breaches I was already aware of (Thanks Forbes!).
- kazinator 12y agoI put in several of my e-mail addresses. E-mail addresses are not secrets and were never intended to act that way, so I don't care if they are harvested. I operate several mailing lists that allow postings from non-subscribers, to addresses that are easily harvestable from the web. Yet, the "mean time between spams" is on the order of many months. I also use my real e-mail address in the From: header of Usenet postings. I simply don't have a problem with spam because of my mail server's terrific anti-spam setup.
- EGreg 12y agoInteresting case of suggestion bias... when faced with such a website name, you are reluctant to give out your email which you would do when signing up to some other site. Except... 1) This site asks for the email address that you CARE about 2) It specifically has people self select for caring about being pwned Therefore it IS more dangerous.
- gk1 12y agoHow is it more dangerous to alert people about their pwnage and encourage them to change their passwords? It's easier to attack someone who doesn't know they're being attacked.
- EGreg 12y agoI can change my password anyway. How would this website possibly know about all the pwnage going on in the world? It doesn't even give details as to what the databases are, until I provide my info. For the record, I am not arguing against THIS particular site, which does seem legit based on the other tabs on the site and the kind of things it talks about, but still, these are general things to keep in mind.
- wglb 12y agoBad guys already have these email addresses. That is the point. And likely the bad guys already know which email addresses you care about. Or it doesn't matter.
- EGreg 12y agoWell for one thing you are providing your email address to a website, which might later sell it as a "high quality" i.e. personal email to receive SPAM. By contrast, when I sign up to a service, I can start out using some throwaway email or a even mailinator.com email. Here, I have to put the ones I care to protect. This is a bit like those services that say "enter your domain name and we'll check if it is registered" and then front-run you in registering it!
- jpalomaki 12y agoSome dark hat guy could use the emails collected on site like this for targeted phishing attacks. Now that I have entered my email there, this reveals that I'm aware of these certain security incidents (the site reported that my email and some personal information had been compromised). Now if somebody would approach me on this topic, they might have a chance of fooling me to give some further details about myself. The benefit from this kind of targeting would be to avoid hitting the spam filters. If they just spammed their message to random addresses, people would flag them as junk mail and good email providers would quickly filter them out.
- kazinator 12y agoPeople who know "pwned" are probably more resistant to phishing attacks than the average schmuck. Also, a lot of the material entered into the site will be fake. This is not a good way to harvest genuine e-mail addresses. Not only is it open to fake addresses, but it is open to deliberate spam-trap addresses: addresses whose only purpose is to detect spam. I can generate a fake address "nothanks@<mydomain>" and feed it to this site (or, generally, allow this address to be widely harvested). Then, whenever an SMTP request comes in with a "RCPT to: nothanks@<mydomain>", I can drop the connection and ban the IP address for 7 days. Any use of that address is 100% spam; no legitimate sender knows this address.
- bitJericho 12y agoIf I were to run this scam, I would only add addresses that were checked and matched a known leak. This would both give me a known good address and also an idea of what kind of person you are. If you're the type to check your email address against known leaks then I would know exactly how to attack you.
- wglb 12y agoThis simply has emails from other lists that have been floating around. For example, the adobe set is from the adobe breach where emails were in the clear. The dark hat guys already have this list. And likely some passwords, which this site doesn't ask for.
- Pxtl 12y agoWonderful site. Also, God dammit Boxee.
- dropdownmenu 12y agoWhat is more interesting is that I can see anyone who has had their accounts breached. I now know that I can collect one of my friend's cell number from the snapchat breach or that an other famous person had his info leaked by Gawker. (edit - punctuation)
- socialist_coder 12y agoMy gmail is in the dump but I changed from that password at least 3 years ago. So, the dump is pretty old.
- freehunter 12y agoAnd mine is listed with a password that I used in combination with the Gmail address as a username, but never as the password to log into Gmail with. So it doesn't seem like this is a dump from Google, but rather from sites requiring email addresses to sign up with.
- mayneack 12y agoLastPass also does this for any accounts you track with them.
- gletard 12y agoDoes what?
- nikbackm 12y agoInteresting. I tested with my gmail-account and it was reported as pwned. Then I tested the gmail-account again with this service which also shows the two first characters of the leaked password. https://isleaked.com/en https://isleaked.com/en Turns out that the leaked "gmail" password was my old password used for unimportant websites and this was never used with the gmail-account itself. So apparently one of those unimportant websites was hacked and the email/password was then grabbed. No way to tell which site that was since haveibeenhacked.com does not include that information, but instead makes it appear that the actual gmail password is/was compromised.
- craigching 12y ago> No way to tell which site that was Hey, that's a great idea! Try and use some indicator in the password you choose so that when your password is revealed you know who it is :) Probably hard to do in practice, but I'm going to keep that in mind next time I visit a site and use a throw-away password
- rogerbinns 12y agoUse a better email service. For example I use my own domain with all email going to me. Consequently I can use site1@my.domain for one site, site2@my.domain for another. Makes it real easy to see who has been sharing things. Gmail lets you use plus suffixes, as well as extra dots: http://gmailblog.blogspot.com/2008/03/2-hidden-ways-to-get-more-from-your.html http://gmailblog.blogspot.com/2008/03/2-hidden-ways-to-get-m...
- craigching 12y ago> Gmail lets you use plus suffixes, as well as extra dots Very nice, thanks for that!
- biggc 12y agoYeah exactly. My gmail password wasn't comprised, just the password I use for throwaway accounts.
- 12y ago
- wglb 12y agoThis was first submitted 480 days ago https://news.ycombinator.com/item?id=6849057 https://news.ycombinator.com/item?id=6849057 and is done by well-respected security researcher Troy Hunt a sometimes HN contributor https://news.ycombinator.com/user?id=troyhunt https://news.ycombinator.com/user?id=troyhunt. The point is that the bad guys already have the stuff that he has put out there. Now you can see as well.
- zinxq 12y agoI tried bob@mailinator.com - totally pwned.
- deadfish 12y agoDoh... I am on there. Anyone have a good way to find all the accounts linked to my email address? I have tried searching for subject:(register | confirm email | activate | account) in my gmail account anyone have a better way?
- JoshTriplett 12y agoLook through your browser or password manager for all the accounts whose randomly generated passwords it remembers. If you're not already generating random passwords and having your browser remember them, now would be a good time to start, since you're finding and updating all your accounts anyway. For the accounts you already have: also include "welcome", "password", and "log in"/"login"/"sign in". You might also search for mail containing your email address in the body. Also skim through the top 1000 sites or so, to jog your memory if you have accounts with those services.
- deleted 12y ago[deleted]
- rey12rey 12y agoGood news — no pwnage found! :)
- cmdrfred 12y agoGreat work, I signed up.