Conversation
Edited 2 years ago

LMAO

If you go to
haveibeenpwned.com

They literally ask you to put in your password, to check if it's been compromised.

Yeah I'm gonna trust you guys who already have a huge big database of stolen passwords, how do you get those exactly?

1
0
1
@big_louse going to the sketchy man in a dark alleyway to know if my SSN is being used by bad people (i had to give him the SSN so he can "check" it)
0
1
1

@mia

right, that's what I mean, they must be pretty well connected to deep web carder markets to keep their db up to date

Sooooo Couldn't they just take those passwords people give them, and sell them? and then turn around and say 'oops your password has been compromised'

Some Sucker: Dammit I keep changing it! How do they keep getting my password?

0
0
0

@quasar

I'm sure, but then you have to just trust they're telling the truth, or that they are doing things as securely as they claim they are.

I guess the alternative is to distribute a big ass sql file, but that would be illegal, so we have to trust the private company who collects stolen information

0
0
0

@mia

Sure, but I'm just inclined to that kind of practice is encouraging bad habits, since you can't possibly expect the average user to examine the API and a lot of 'trusted' companies have been totally pwned or exposed as criminals themself.

Putting in one's email or social media account or other information is might be acceptable, but the pw itself?

0
0
0

@quasar

well they word it like this

{ HaveIBeenPwned.com (HIBP) is owned and operated by Superlative Enterprises Pty Ltd ABN 62 085 442 020 ("Superlative", "we" or "us" }

https://haveibeenpwned.com/Privacy

0
0
1