With the latest data added to #haveIbeenpwned I found out that #Dropbox lost my credentials a second time. 😔

So make sure to check #HIBP webpage with your email addresses and/or your domain to find out which services got hacked.

So I just deleted all my Dropbox data (I haven't used for 13 years because of #Syncthing) in their web interface, changed the password, added 2FA (TOTP) and unlinked all my (outdated) devices. Bye Dropbox! 👋

Hups, ein bekanntermaßen unsicheres Passwort ergibt eine erstaunlich hohe neunstellige Zahl Treffer:

> This password has been seen 179,863,340 times before in data breaches!

https://haveibeenpwned.com/Passwords

#haveibeenpwned #passwort

Der Betreiber gilt als vertrauenswürdig und hat die Prüfung technisch recht gut abgesichert, so dass nie das Passwort übertragen wird. Im Zweifel lokal prüfen, die Datenbank steht dafür zum Download zur Verfügung (ist aber groß).

Have I Been Pwned: Pwned Passwords

Pwned Passwords is a huge corpus of previously breached passwords made freely available to help services block them from being used again.

Have I Been Pwned

»Have I Been Pwned — Milliarden neuer Passwörter in Sammlung:
Aus Infostealer-Datensätzen konnte Have-I-Been-Pwned-Betreiber Troy Hunt 1,3 Milliarden einzigartige Passwörter extrahieren.«

Ich weise schon lange auf @haveibeenpwned hin und auch wenn die Menschen sich als gehackt erkennen, haben sie scheinbar immer noch nichts zu verbergen. Wann nehmen dies die es endlich ernst oder/und verwenden Passkeys?!

🔓 https://www.heise.de/news/Have-I-Been-Pwned-Milliarden-neuer-Passwoerter-in-Sammlung-11067453.html

#email #haveibeenpwned #passwort #hacking #online #datenschutz

Have I Been Pwned: Milliarden neuer Passwörter in Sammlung

Aus Infostealer-Datensätzen konnte Have-I-Been-Pwned-Betreiber Troy Hunt 1,3 Milliarden einzigartige Passwörter extrahieren.

heise online
Have I Been Pwned: Milliarden neuer Passwörter in Sammlung | heise online
https://heise.de/-11067453 #HaveIBeenPwned #Passwörter #Datenschutz

I'm a bit annoyed by what's effectively a sales email process from #haveibeenpwned - notification that an email+password on my personal domain was found in the #Synthient breach. Follow the link, enter the address used to confirm domain ownership, wait for a second email, follow the link, get nothing useful just "Insufficient subscription. Only subscription-free breaches will be returned for this domain."

I'm not feeling a need to pay $4.50/mo to find out which of my per-domain email addresses with unique passwords was breached, nor do I need to run 10 searches per minute.

Have I Been Pwned logs 17.6M Victims in Prosper Breach.

HIBP alleges that email addresses — as expected — were affected, as well as a slew of other personal information.

This included:

• Browser user agent details
• Credit status information
• Dates of birth
• Employment statuses
• Government-issued IDs
• Income levels
• IP addresses
• Names
• Physical addresses

https://haveibeenpwned.com/Breach/Prosper

#prosper #breach #haveibeenpwned #it #security #privacy #engineer #media #tech #news

Ugh, the disadvantage of having a separate mail address for every organisation I interact with:
#haveIbeenpwned now asks me money to see which of those has been leaked
Funny how in 10 years just the same 10 email-addressses end up in spam lists.
No new ones added, no other domain.
I could shut down one domain and have all the spam gone.

Also it's funny to see them in these lists, but what is the danger for me with this?
Mostly just more spam for the filter.
Apart from that? Pretty much nothing if your mailserver is configured with all the bells and whistles.

So for me it's just interesting to see, but not a service I whould give 220 USD / year / domain for, as an individual.
Also just because I privately do own domains, I'm not a business.

12 $ per domain per year is something I whould pay at max for that.

#HaveIBeenPwned #ReallyUsefulOrJUstInteresting
2 Billion Email Addresses Were Exposed, and We Indexed Them All in Have I Been Pwned - Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get ... https://www.troyhunt.com/2-billion-email-addresses-were-exposed-and-we-indexed-them-all-in-have-i-been-pwned/ #haveibeenpwned
2 Billion Email Addresses Were Exposed, and We Indexed Them All in Have I Been Pwned

I hate hyperbolic news headlines about data breaches, but for the "2 Billion Email Addresses" headline to be hyperbolic, it'd need to be exaggerated or overstated - and it isn't. It's rounded up from the more precise number of 1,957,476,021 unique email addresses, but other than that,

Troy Hunt