The best site to find password leaks: Google
google.com
google.com
Your statement assumes that security through obscurity is a good thing.
Someone ought to write a tool that follows this account, and e-mails people warning them that their e-mail has been compromised.
The hard part would be explaining what happened, how to verify it, and how to fix it to random strangers without convincing them that you're the one who just tried to steal their life savings.
Honestly though, google shouldn't even have to worry about these things, their mission is to organize data on the web. If it is there, it should be searchable.
There is also a pretty good book from a spanish Microsoft MVP (yeah it sounds bad but still its an important award, :\)
http://www.informatica64.com/libros.aspx?id=hackingBuscadore...
It's a shame they decided not to translate it, anyone is up to it here? It contains everything that you'd ever wonder and much more.
Title: Search Engine Hacking with Google, Bing & Shodan Author: Enrique Rando
Pages: 272
Price: 20 Euros + Shipping (includes IVA)
Though it's been 2500 years since Sun Tzu wrote "The Art of War", many of his lessons remain relevant. His teaching contains several passages that seem especially suitable for people who work in Information Security:
* "Those who disable foreign armies without combat are the best teachers of the Art of War."
* "Before you fight, first learn the skills of the enemy's workers, and then fight them according to their weaknesses."
* "When you can perceive subtlety, winning is easy."
Without a doubt, this information is key in preparing for attempted security breaches. Without it, determining what to attack and how to do it is impossible. Search engines have become important tools for collecting data and other intelligence. However, despite Google hacking's many years of use, its techniques have perhaps not always been well-treated or publically shared.
Also, sometimes an index.html file is accidentally removed, causing (brain-dead installs) to suddenly reveal the contents of a directory, eg. http://shahinfosoft.com/
As someone else mentioned, Johnny posted articles on this years ago. But, he merely popularized it, Google hacking was around long before him.
See also: filetype:mdb, filetype:xls, "ssn" and so on.
For music, try: metallica filetype:mp3 For books, try: oreilly filetype:epub (or whatever)
see the on at http://news.ycombinator.com/item?id=2704359
http://www.google.com/search?hl=en&tbo=1&biw=1315...
(SFW-ish; no images, just links to really sleazy websites)
This is doubly true with security. There is no cosmetic or usability difference between a secure application and a nightmare that leads to thousands of leaked passwords. So companies that don't already have a good group of developers are screwed when hiring, and companies that don't consider their existing team's decision as the most important factor when hiring are asking for trouble.
Also, it's not a matter of development, but security and system administration. They are often performed not only by different people, but sometimes even by different sub-organizations in different physical locations. It's not a good excuse, but we shouldn't be so quick to judge developers author knowing what exactly happened.
Otherwise a password-not-yet-leaked will no longer be. If you didn't turn on private browsing as I suggested and are using Safari, type the password you searched for in your URL bar now and you will see why I said what I said.
And for that matter, why do you have so few that you can easily google for them instead of generating random ones per site?
(Fun fact, googling for your e-mail address reveals a hash of your password on MtGox.)
For that matter, I have a unique password (with the necessary special characters) for each account that associates with my identity (Not naming any examples here), but only several unique passwords for websites I don't intend to use much e.g. to read newspapers, and apparently, MtGox.
(Yes, I was searching for my MtGox. password because it was the same password I used for random throwaway sites. No I never used it, I don't even remember having confirmed my account there. My asset in bitcoins amount to < $2 USD.)
I still don't understand why all the downvotes. It would've helped me if someone reminded me not to actually google my password with my browser watching. Apparently not anyone else.
EDIT: I, however, do not agree that it is necessary, even more being a link posted on HN
edit: definitely downmod to make an example.