TE
ТехЭхо
ГлавнаяТоп за 24 часаНовейшиеЛучшиеВопросыПоказатьВакансии
GitHubTwitter
Главная

ТехЭхо

Платформа технологических новостей, созданная с использованием Next.js, предоставляющая глобальные технологические новости и обсуждения.

GitHubTwitter

Главная

ГлавнаяНовейшиеЛучшиеВопросыПоказатьВакансии

Ресурсы

HackerNews APIОригинальный HackerNewsNext.js

© 2025 ТехЭхо. Все права защищены.

Have I Been Pwned 2.0

875 балловавтор: LorenDB6 дней назад

52 comments

neilv6 дней назад
He should partner with a law firm, for class action lawsuits, for every breach due to negligence (which is probably all of them).<p>Tie in to a banking service, so you can do direct deposits to many millions of people, every time there&#x27;s new settlements paid, and you&#x27;ll be a folk hero.<p>Get lawyers who want negligent companies to actually regret the breaches, with judgements that hurt. (Rather than a small settlement that gets lawyers paid, but is only a small cost of doing business, which is preferable to doing business responsibly.)<p>Optional: Sell data of imminent lawsuits, to an investment firm.<p>Though, ideally, investors won&#x27;t need this data, since everyone will know that a breach means a stock should take a hit. Isn&#x27;t that how it should be.
评论 #44041808 未加载
评论 #44035887 未加载
评论 #44036327 未加载
评论 #44036567 未加载
评论 #44039475 未加载
评论 #44039512 未加载
评论 #44036345 未加载
评论 #44037792 未加载
评论 #44036965 未加载
评论 #44043318 未加载
评论 #44073617 未加载
评论 #44037031 未加载
stevekemp5 дней назад
Like many people I have a &quot;main&quot; email address, and I use per-company addresses for almost everything else. Now that the domain-searches require subscriptions this site has become much less useful.<p>I just added my domain to the site again and I see &quot;2,243 Total Breached Addresses&quot;, and &quot;18 Addresses excluding Spam Lists&quot;, but I have no idea what they are. Attempting to click the links shows me I need to &quot;upgrade&quot; to see them, and the download of excel and JSON result in 404 errors.<p>Too bad, I guess if you have only a single email address it might be good to get informed, but if you use a domain with multiple addresses it&#x27;s way less useful.
评论 #44039530 未加载
评论 #44042690 未加载
评论 #44040036 未加载
评论 #44041081 未加载
评论 #44040820 未加载
Aachen5 дней назад
&gt; It&#x27;s likely a single-digit percentage of requests that are real humans being [blocked], and we need to look at ways to get that number down, but at least the fallback positions are improved now.<p>The fallback suggestions mentioned in the article are &quot;try clicking the box again&quot; and &quot;try reloading the page&quot;<p>I&#x27;m slowly starting to wonder if I should start sending snail mail to companies that block me, instead of resigning to go somewhere else. HIBP is a free web service and shops have no obligation to serve a given individual, but it everyone puts CloudFlare Turnstile, Google Recaptcha, etc. in front of their services, a &quot;single-digit percentage&quot; of people simply cannot participate in modern society. Similar markers (IP address misclassified as bot range, unusual&#x2F;old&#x2F;infected browser, ...) will constantly be triggering for the same group
评论 #44044604 未加载
评论 #44043397 未加载
评论 #44040171 未加载
85392_school6 дней назад
Does anyone else feel like the new design feels less trustworthy? I&#x27;ve probably just been conditioned on too many templates that all look the same, and there&#x27;s nothing inherently wrong with it, yet it makes me wonder if I&#x27;ve accidentally opened a ripoff instead of the real thing.
评论 #44035724 未加载
评论 #44039339 未加载
评论 #44046650 未加载
AdamH121136 дней назад
Amazing that even within the last decade a site as large as LinkedIn could be storing unsalted passwords. How does anyone fail at this in the modern era?
评论 #44036183 未加载
评论 #44035710 未加载
评论 #44037107 未加载
评论 #44040447 未加载
评论 #44056013 未加载
评论 #44044731 未加载
评论 #44035708 未加载
评论 #44036074 未加载
micw5 дней назад
Unfortunately the new UI does not allow to search for leaked phone numbers anymore. The old did (e.g. could check for facebook phone number leak, see <a href="https:&#x2F;&#x2F;www.troyhunt.com&#x2F;the-facebook-phone-numbers-are-now-searchable-in-have-i-been-pwned&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.troyhunt.com&#x2F;the-facebook-phone-numbers-are-now-...</a>). The new does not let it pass through the input field.<p>Edit: it&#x27;s also statet in the announcement:<p>&gt; Just one little thing first - we&#x27;ve dropped username and phone number search support from the website<p>But it&#x27;s really a bad time to remove this feature since there&#x27;s a ongoing law suite against facebook in germany (<a href="https:&#x2F;&#x2F;www.vzbv.de&#x2F;pressemitteilungen&#x2F;facebook-datenleck-betroffene-koennen-sich-der-sammelklage-des-vzbv-anschliessen" rel="nofollow">https:&#x2F;&#x2F;www.vzbv.de&#x2F;pressemitteilungen&#x2F;facebook-datenleck-be...</a>, hgerman link) that utilized the search there to know if one can participate or not.
评论 #44038762 未加载
standardUser6 дней назад
It shows you a vertically scrolling timeline (with logos and blurbs) of all the data breaches that have exposed your email. How delightfully horrifying.
评论 #44035649 未加载
nikcub5 дней назад
Lots of regular people use Have I Been Pwned and sending them to 1Password is probably the single best thing you could do for them (I know it&#x27;s a sponsorship - but it&#x27;s a very complimentary one).<p>I&#x27;d make the language around that promo banner stronger (ie. &quot;We strongly recommend&quot;) and make it stand out more on the page.<p>So many social media accounts get hacked[0] because of shared passwords and those affected users often end up on the site - funnelling them to a password manager and a reason why it&#x27;s good hygiene is great.<p>ps. congrats on the relaunch!<p>[0] I&#x27;ve probably assisted 20+ such cases in the past ~12 months
评论 #44038863 未加载
评论 #44038687 未加载
YPPH6 дней назад
For those who would prefer to stay a little more under the radar, you can hide results from a search of your email appearing on this service.<p><a href="https:&#x2F;&#x2F;haveibeenpwned.com&#x2F;OptOut" rel="nofollow">https:&#x2F;&#x2F;haveibeenpwned.com&#x2F;OptOut</a>
评论 #44037131 未加载
评论 #44037278 未加载
brightball5 дней назад
Does it feel like this site is itself a vulnerability? It seems like being able to go type in anybody&#x27;s email address and just get a list of sites where it was found would be part of an OSINT process.<p>Shouldn&#x27;t it at least send you a link to verify that you control the address before showing your results?
评论 #44041926 未加载
评论 #44041668 未加载
评论 #44041748 未加载
评论 #44045676 未加载
评论 #44041643 未加载
评论 #44041602 未加载
diggan6 дней назад
Who has the record for being in the most breaches? My main email seems to currently be in 40 breaches, earliest one in from June 2011 (HackForums, don&#x27;t even remember what that is), and last one in September 2024 (FrenchCitizens, although I&#x27;m not French nor have I ever lived in France).
评论 #44037308 未加载
评论 #44036371 未加载
评论 #44037053 未加载
评论 #44056058 未加载
评论 #44036140 未加载
评论 #44037859 未加载
评论 #44039485 未加载
keybored5 дней назад
&gt; The AI<p>&gt; I wanted to make a quick note of this here, as AI seems to be either constantly overblown or denigrated.<p>This just gestures at middle-of-the-road thinking.<p>So what’s this begrudging note about? To set us on the correct course in the middle of the road?<p>&gt; I&#x27;d say it was right 90% of the time, too, and if you&#x27;re not using AI aggressively in your software development work now (and I&#x27;m sure there are much better ways, too) I&#x27;m pretty confident in saying &quot;you&#x27;re doing it wrong&quot;.<p>Well done. AI plug done.<p>I don’t see how that statement fulfills the implied middle-of-the-road opinion though.
randunel5 дней назад
New HIBP, same old restriction banning users from 3rd world countries <a href="https:&#x2F;&#x2F;imgur.com&#x2F;a&#x2F;AzNSreV" rel="nofollow">https:&#x2F;&#x2F;imgur.com&#x2F;a&#x2F;AzNSreV</a>
评论 #44039368 未加载
评论 #44043137 未加载
kmarc5 дней назад
The &#x27;;-- in front of Pwned is a brilliant idea but less brilliant execution. Missed opportunity, I&#x27;m wondering how many people don&#x27;t realize what it is
评论 #44039403 未加载
评论 #44038130 未加载
评论 #44041573 未加载
nipperkinfeet6 дней назад
Too much scrolling. I prefer the old page.
评论 #44044499 未加载
评论 #44035721 未加载
mNovak6 дней назад
Is there a term for this trend in web design, with defaulting to dark mode and having slick gradients everywhere?
评论 #44037361 未加载
评论 #44035617 未加载
评论 #44041202 未加载
评论 #44035792 未加载
BubbleRings5 дней назад
I’ve never been able to figure out how haveibeenpwned.com can be useful to me, since I have had the same email address for many years and I don’t want to give it up. Do people get a new primary email address every time their address shows up in a breach list like haveibeenpwned ?
评论 #44037090 未加载
评论 #44037048 未加载
评论 #44037636 未加载
评论 #44039500 未加载
评论 #44037035 未加载
评论 #44037069 未加载
mslev6 дней назад
The new design looks great, and I always love following Troy&#x27;s updates (although sometimes with semi-morbid curiosity).<p>I do find the timeline to be a little confusing- it seems to be ordered from earliest breach to most recent, but the dates on the timeline don&#x27;t match that, as they seem to be when the data was leaked?<p>Display: breach date Ordering: breach published date?<p>I think it might be clearer to order + display the published date, and in the cards themselves show the breach date in a standard way.
greatgib5 дней назад
I was always frustrated by this service because it is good to tell you that you have been pwned and your email appears in a breach but sadly it is more often than not more scary than useful as you can&#x27;t see exactly what has been leaked about you. Especially your password.<p>I understand the rational to hide the details, but bad actors like criminal probably have the source file with the details anyway.<p>What annoys me is that it is good to know that your email appears in a random pastebin agglomerating hundreds of leaks but if they don&#x27;t give the exact name and date of the site, and without seeing the password it is hard to know who leaked your data and which password to change.<p>The worse is that I was used to use a very shitty simple password for all the sites that ask one without needing one (let&#x27;s say media with free subscription needed to read a single article, Free conference or online webinar), ... and these one are the best targets to have leaks despite them being totally harmless if you take care to not give your personal info inside.
CobrastanJorji6 дней назад
Very cool.<p>Small bug report: I&#x27;ve been pwnd a few dozens times, and my timeline is not in calendar order. I see Adobe (October 2013), then LinkedIn (May 2012), then Dropbox (June 2012), then Lastfm (March 2012), then some 2016 ones, then Kickstarter in 2014, and then after that they start being more in order of the listed dates.
评论 #44036235 未加载
santiagobasulto5 дней назад
When it mentions that your password has been leaked for a service, is this the plain text pwd (that service somehow stored that way) or is it a hash? Was the website salting the passwords (so no rainbow-table attack could happen)? What key derivation function were they using? Etc...<p>I feel the red circle with &quot;Password compromised&quot; is way too simplistic if this wants to be a TRUE trusty site regarding cybersecurity. If they just want to show fear and sell 1Password ads, I understand it, I won&#x27;t consult it anymore. But if they want to really step up their game from a technical perspective, they should include more details.
评论 #44046647 未加载
评论 #44042439 未加载
jmward015 дней назад
This is a great site. Thanks for making it! I wish governments would take this kind of thing seriously though. Identity theft&#x2F;stealing accounts&#x2F;etc etc all starts with breaches like this and in the modern world it is often less devastating to have someone break into your house than to break into your digital life. With a break in you will get actual support in the form of a phone number to call (911 in the US) and real people doing real work to track down who did it and stop them. With the digital world you have nobody to call and even if you did I doubt much followup would happen. Society needs to change gears on this stuff and actually take it seriously.
benob5 дней назад
Ok, one of my email addresses is in a bunch of leaks. What is interesting is that most services on this list I have never used. How did they get my email in the first place? What is the accuracy of that whole business?
dsissitka6 дней назад
&gt; But now it&#x27;s on a timeline you can scroll through in reverse chronological order, with each breach summarising what happened.<p>Maybe I&#x27;m reading it wrong but it looks like it might be a little off. I get:<p>- October 2013<p>- June 2008<p>- ...a bunch more...<p>- November 2021<p>- December 2020
评论 #44035854 未加载
skarz5 дней назад
What&#x27;s the best service or app for tracking data breaches where your username and password are leaked? I&#x27;m trying to mitigate some leaks through ProtonPass but it&#x27;s very frustrating as they simply say &quot;password ****123 was found on the dark web&quot; (they actually redact the full password) so then I manually have to go through my 100+ passwords and look for that particular password.
giancarlostoro5 дней назад
I keep wondering if its smart to just roll over an email address when it gets compromised, and limit your exposure, as well as force you to change your password while you&#x27;re on every website ditching your former email.<p>I know some people use email tags, but maybe just rolling a new email might be better, followed by deleting unused dead accounts you will never use again.
robertlagrant5 дней назад
I just very much appreciate a regular gaming typo having made such a cultural impact over the last 25 years.
rtrgrd6 дней назад
Am I the only one who is experiencing severe lag when scrolling on the new site (Firefox android)?
评论 #44046673 未加载
BurnGpuBurn5 дней назад
1) The search function has disappeared from the home page.<p>2) When clicking &quot;details&quot; on one of the search results, and then the back button, the search results disappear.<p>3) Other than that, thanks man great service!
luchris4295 дней назад
I love this site! Though I do wonder how much this site also helps amateur hackers find where to search for a specific person&#x27;s password. One way to deal with it could be to email the person their pwns.
评论 #44037071 未加载
tech234a6 дней назад
I regularly use plus codes on my email addresses when I sign up for services, is there a way to search for an email address and all associated plus codes? Last I checked I couldn’t find that functionality.
评论 #44035806 未加载
paulnpace5 дней назад
I just verified that this database does not include the Vultr breach, or, at least it does not include email addresses that are unique to the Vultr service.
评论 #44041960 未加载
rasz6 дней назад
<p><pre><code> Uncaught (in promise) Error: Invalid response from fetch: 401 - at emailSearch.ts:295:19 at async HTMLButtonElement.&lt;anonymous&gt; (emailSearch.ts:43:23)</code></pre>
glandium5 дней назад
There&#x27;s something interesting in the domain search: some breaches contain addresses that... simply don&#x27;t exist. Like B2BUSABusinesses has sales@mydomain.
Buttons8406 дней назад
A lot of companies I&#x27;ve never heard of before are leaking my data. :(<p>Can we make it so that companies I&#x27;ve never heard of before don&#x27;t have my data in the first place?
评论 #44036027 未加载
评论 #44036032 未加载
Saris5 дней назад
I really wish I could put in my domain name, I have so many aliases that it&#x27;s basically impossible to search each one individually.
评论 #44036782 未加载
babuloseo5 дней назад
Lol I was looking at recently or yesterday and was wondering why it looked more nicer and usable than usual heh.
WhereIsTheTruth5 дней назад
It&#x27;s funny how you can find someone&#x27;s interests just by typing his&#x2F;her email address<p>The ultimate tracking tool
msephton5 дней назад
Interestingly, the timeline is not chronological for me? I can&#x27;t seem to figure it out the order it is in.
Squeeeez5 дней назад
Does anyone feel like paying $274 and checking if the domains search allows gmail, hotmail etc? :o)
评论 #44039515 未加载
bstsb5 дней назад
i like the new design, but it feels that the &quot;stats&quot; like the cache hit ratio and edge locations won&#x27;t matter to the vast majority of visitors, who are just trying to check for potential breaches.<p>on the other hand, they will be great for the api&#x2F;business pages
bix65 дней назад
Awesome! My timeline is showing out of order though (starts with a 2013 then a 2019 then a 2011).
l725 дней назад
I use a lot of email+site@example.com. It would be great if those were included too!
hanatanaka19845 дней назад
Great service. I use regularly with extended family to convince use of MFA.
评论 #44036924 未加载
charcircuit6 дней назад
This new design no longer links to the pastebins you were included in.
评论 #44036018 未加载
gherkinnn5 дней назад
<a href="https:&#x2F;&#x2F;haveibeenpwned.com&#x2F;Passwords" rel="nofollow">https:&#x2F;&#x2F;haveibeenpwned.com&#x2F;Passwords</a><p>Checking the passwords, &quot;password&quot; has been pwned &gt;21 million times. I don&#x27;t know what I expected.
yieldcrv5 дней назад
Too bad the term pwned dates us now<p>I think we’re backed to hacked
h1fra6 дней назад
nit: timeline should be most recent to least recent
geor9e5 дней назад
The input box doesn&#x27;t work
xlbuttplug25 дней назад
Now waiting for this website to get pwned for its search history so hackers can identify targets worth pursuing.
johnklos5 дней назад
I really wish Troy would&#x27;ve put a little more thought in to this before deciding to host using a for-profit corporation based in the US that wants to be a monopoly.<p>Will Cloudflare sell data to US TLA agencies? Probably.
willmarquis5 дней назад
Really impressive evolution of a crucial service. The architectural and UX improvements are well thought out, especially the focus on resilience and scalability. Love the transparency around the decision-making process, too-Troy’s commitment to keeping HIBP fast, free, and useful is a great example of public-interest software done right. The migration to .NET 8 and use of Cloudflare for caching shows how mature and modern the stack is becoming.