1.4B records from “Have I been pwned” for analysis
troyhunt.com
troyhunt.com
What might be interesting is graphing a network of the relationship between services which suffered a breach. Fortunately, I have the proper workflow prepared to process the data in this manner, so I'll take a look.
The difference between your first draft[1] and mine is that I've only included links where each site had at least 1% of users in the other site. This helps make links more meaningful.
For instance, about 37k users were members of both Tumblr and Plex. Tumblr had the largest number of Plex users, so it should be a strong link, right? No: because Tumblr has such a large userbase, this is a relatively insignificant relationship; 0.14% of Tumblr users had Plex accounts, which ranks only 20th for Plex.
Compare this to Plex and Xbox-Scene. 5.6k users had Plex and Xbox-Scene accounts, which is about 2% of each site's userbase. I believe this link is much more meaningful than the Plex-Tumblr link, and I believe my visualisation bears this out.
[1]http://i.imgur.com/FpLiFGk.png
* Note: since I ignored all lines with only one site, this "1%" only includes users who were in more than one breach!
I'd feed it into my bad-password-indexing program (https://github.com/robsheldon/bad-passwords-index) and it would spit out a file that could be used to improve password security in a not-entirely-stupid way somewhere.
I can (and should) start tracking down more password dumps and compiling them myself to do the same thing, but I've been spread pretty thin for a while. It's been on my mind but there hasn't been time for it.
A massive list of plaintext passwords from Troy's dump, the ones that were available anyway, would have been really convenient. Odds are my index file would already be updated to a newer version.
I might be onto something. It appears the communities algorithm correctly detected the Russian and China communities.
haveibeenpwned is a helpful and legit site, though I think it should have used email confirmation instead of requiring only an email address.
I also respect Troy along with many other security researchers. Even those that are up to no good in the security world in some ways have contributed good things; after all, the rest of us are stronger and more vigilant now than we used to be because of their work.
However, this anonymized data will almost certainly be used by black hats more than white hats, and I don't see how this release is good for the majority of those that were affected by these breaches.
Doubtless there are black market tools that provide such a service but expose far more data, but haveibeenpwned lowers the barrier to entry significantly by being far more available to the public.
You definitely have to change password, or even use password manager. But your record is now widely available it feels as you have been naked on the Internet.
You may likely change your email address ( Login Name ). But opening another email account is such an hassle. An opening yet another account on those of your favorite site means you lost all of your pass record.
I would love to know which DNS provider has the best security if anyone has done the research.
Running your own registrar gets tricky, however.
I've come to assume some non-zero percentage of sales/marketing/lead gen companies are using this as a go-between for an SMTP validator.
Or even better, build the service you're asking for! Clearly, there's a need.