Ask HN: I found a way to find thousands of emails/pwds. Now what?
While doing a bit of research for a blog article, I created a way to find thousands of new valid emails / passwords every day. The method I used and the scripts I wrote are actually very basic and common sense, and mostly rely on the fact that there is an easy way to find passwords that are poorly chosen. Now I am a bit torn about what to do. In a sense I would like to warn people (even though those warnings have already been said thousands of times) about this whole thing. But on another hand, putting out that information to the public would only be detrimental to all those people whose credentials would all of a sudden be out in the open for everyone to abuse. There is also the legal issue and I am in no way trying to get close to doing something stupid. Also this is not a case where I can issue a responsible disclosure as the information is found through 1/ weak passwords by random people, 2/ weak encryption by random organizations. Should I just let the whole thing go and concentrate on something else? Please advise. Thanks.