Have I been pwned? Check if you have an account that has been compromised
haveibeenpwned.com
haveibeenpwned.com
The point is that the bad guys already have the stuff that he has put out there. Now you can see as well.
Maybe that's the next website to build: willihavebeenpwnd.com and then whenwillibepwnd.com
Would you put your credit card info on a business card and give it to people you meet?
Of course not, I just hand it to the minimum wage cashier, say it over the phone whenever I am ordering delivery, and type it into online stores.
Now if they wanted to supply a list of hashes to the public, then you could check your own without knowing any of the other addresses used to generate the remaining hashes.
If I wanted to be truly malicious I'd have my online checker return a "Nope, you're all good" and then add that email address to the short list of accounts to go after.
I tested with my gmail-account and it was reported as pwned.
Then I tested the gmail-account again with this service which also shows the two first characters of the leaked password.
Turns out that the leaked "gmail" password was my old password used for unimportant websites and this was never used with the gmail-account itself. So apparently one of those unimportant websites was hacked and the email/password was then grabbed. No way to tell which site that was since haveibeenhacked.com does not include that information, but instead makes it appear that the actual gmail password is/was compromised.
Hey, that's a great idea! Try and use some indicator in the password you choose so that when your password is revealed you know who it is :) Probably hard to do in practice, but I'm going to keep that in mind next time I visit a site and use a throw-away password
Gmail lets you use plus suffixes, as well as extra dots: http://gmailblog.blogspot.com/2008/03/2-hidden-ways-to-get-m...
Very nice, thanks for that!
Now if somebody would approach me on this topic, they might have a chance of fooling me to give some further details about myself.
The benefit from this kind of targeting would be to avoid hitting the spam filters. If they just spammed their message to random addresses, people would flag them as junk mail and good email providers would quickly filter them out.
Also, a lot of the material entered into the site will be fake. This is not a good way to harvest genuine e-mail addresses.
Not only is it open to fake addresses, but it is open to deliberate spam-trap addresses: addresses whose only purpose is to detect spam. I can generate a fake address "nothanks@<mydomain>" and feed it to this site (or, generally, allow this address to be widely harvested).
Then, whenever an SMTP request comes in with a "RCPT to: nothanks@<mydomain>", I can drop the connection and ban the IP address for 7 days. Any use of that address is 100% spam; no legitimate sender knows this address.
The dark hat guys already have this list. And likely some passwords, which this site doesn't ask for.
They would know that you know that they know.
This means they could be very, very targeted with an email/social phishing attack to try and get a newer password or other account information by referencing the previously compromised site. It could help the bad guys establish trust. A bit tinfoily but well within the realm of possibilities if the lookups on this site are logged.
I now know that I can collect one of my friend's cell number from the snapchat breach or that an other famous person had his info leaked by Gawker.
(edit - punctuation)
subject:(register | confirm email | activate | account)
in my gmail account anyone have a better way?
For the accounts you already have: also include "welcome", "password", and "log in"/"login"/"sign in". You might also search for mail containing your email address in the body.
Also skim through the top 1000 sites or so, to jog your memory if you have accounts with those services.
1) This site asks for the email address that you CARE about
2) It specifically has people self select for caring about being pwned
Therefore it IS more dangerous.
For the record, I am not arguing against THIS particular site, which does seem legit based on the other tabs on the site and the kind of things it talks about, but still, these are general things to keep in mind.
By contrast, when I sign up to a service, I can start out using some throwaway email or a even mailinator.com email. Here, I have to put the ones I care to protect.
This is a bit like those services that say "enter your domain name and we'll check if it is registered" and then front-run you in registering it!
Doesn't raise any red flags for me. As someone else pointed out, it's trivial for someone to collect emails or find your email. Heck, this latest dump has 5 million of them...
E-mail addresses are not secrets and were never intended to act that way, so I don't care if they are harvested.
I operate several mailing lists that allow postings from non-subscribers, to addresses that are easily harvestable from the web. Yet, the "mean time between spams" is on the order of many months.
I also use my real e-mail address in the From: header of Usenet postings.
I simply don't have a problem with spam because of my mail server's terrific anti-spam setup.
Also, God dammit Boxee.