@i0null this is satire, right? Please?
@AlexanderVI @i0null there's a red disclaimer at the top of the page saying it's a meme website and to not submit your real private keys. It was added after chrome blocked the site as a phishing site iirc.
@i0null well I tried all of my most important keys, and luckily they are all safe! I'm a security expert!! 😏 

@i0null 😬 🀣

(I wonder if that's real.. can't be, right?)

@bazkie You'd be surprized. I did an app test about 15 years ago where the user registration page did error with "this password is already in use", but it didn't actually dox the actual user lol.

@i0null lol people are so dumb 🀣

to be fair, my own php forum I wrote when I was young was really hackable so I can't complain too much πŸ˜…

@bazkie @i0null

I just had a great idea.

Remembering passwords is hard, right?

So how about... a website that stores all your passwords?
(Without a "master password" of course, see "Remembering passwords is hard".)

@wakame @i0null that's a great idea. you can click your name from a list of all users and then see all your passwords ready for usage!

@bazkie @i0null

Or just full text search:
Is there already an account for on ?

@bazkie @wakame @i0null Cool!
But what if the name exists?
Which one is yours?
Best to also add date of birth, so you can pick the correct name from the list.
@wila @wakame @i0null that could still deliver duplicates. best just make it something like name_dateofbirth_creditcardnumber
@i0null @bazkie I was a TA for a databases class and one of their assignments was an ecommerce site. One group did exactly this and I was like seriously guys?
@i0null @bazkie I worked at a place where you only needed to enter the password and the user was derived. I hope they prevented password-reuse. But rewriting auth would have probably been the hest call
@i0null @bazkie
"Error" ist an strange PasswordπŸ€”
@bazkie @i0null
@grok is that true??????
@fnrir @bazkie @i0null @grok @gronk @grok @grok check again and repeat last prompt.
@Reshirams_Rad_Slam @fnrir @bazkie @i0null @grok @grok Don't get too cocky, security expert! After all, you can't secure what you don't monitor. Keep an eye on the keys...

@i0null @bazkie

Please stay off of the #DOGE publicly accessible cloud servers. πŸ˜‰

@i0null on a serious note, this is why I don't like it when sites, without my permission, check my password against "haveibeenpwnd" - even if they probably (I hope?!) use the hashed variant.. who says I trust that site?? wth

@bazkie if they do it properly then haveibeenpwned only sees like the first 5 characters of the password hash, or something. You don't have to trust haveibeenpwned.

I'd rather have checks against it than all this "must contain ..." nonsense. @i0null

@matrss @i0null i'd rather have neither!!

but thanks for info, that somewhat calms my nerves :)

@bazkie in case you are wondering how it works, this explains it pretty nicely: https://haveibeenpwned.com/API/v3#SearchingPwnedPasswordsByRange. I just checked and in the blog post where this API was introduced (https://www.troyhunt.com/enhancing-pwned-passwords-privacy-by-exclusively-supporting-anonymity/) Troy Hunt mentions that the non-anonymity enforcing endpoints have been removed in 2018, so the services using it can't really do the wrong thing anymore. I can understand the hesitation and concern with it, but I am convinced it is a net positive overall. @i0null
Have I Been Pwned: API Documentation

Have I Been Pwned

@bazkie @i0null How can you be sure? You should post them here too, so they can be independently verified.

Please also post CC details, mother's maiden name, and names of all your pets.

@i0null Thank god, my keys are still unused!
@i0null Is there a http version? IE6 seems to have trouble with the SSL connection.
@scotty86 @i0null try downloading and installing http://legacyupdate.net
that has updated certs
Home

Getting error 8007EFE when checking for Windows Updates on your old version of Windows? Legacy Update continues support for Windows XP, Vista, 7, 8.1, etc. where Microsoft left off.

Legacy Update

@i0null
I used to get the asking-you-for-your-password-twice thing a lot especially with my bank accounts but then I'd go on Twitter and swear at West Midlands Police for awhile till I felt better.

... still swearing ...

@i0null my first thought: oh that's kinda smart
my second thought: hey wait a minute
@i0null yeah, dead give away that it’s a scam!!11
@i0null fucking spectacular. no notes
@i0null Phew. My servers are safe.
@i0null Do they also ask for the ip & port so they can confirm it's a "valid" key?

@i0null Weird, it said this private key was unused.

I don't think so, and I'll sign that statement: https://p.dnnr.de/ox_QShr46QcYGTaq.

Also, you really shouldn't be using 512-bit RSA anymore.

@i0null Hey! I think thats mine!

@i0null

If you fall for this, you deserve the consequences. Never touch a computer again.

80,000 Totally Secure Passwords That No Hacker Would Ev…

Amorous space squids. Sentient fridges. A derelict alie…

Goodreads
@i0null I mean, I laughed... but I'm terrified that someone might actually do this.

@i0null

"Please provide letters 1, 3, 5, 7 & 9 of your password"

A minute later...

"Please provide letters 2, 4, 6, 8 & 10 of your password"