Jörg · @JoergA
90 followers · 1535 posts · Server social.tchncs.de

Fremde Nutzerdaten sind noch immer über eine öffentliche bei abfragbar: blackowlintelligence.com/osint
Diese wurden vor einiger Zeit massenhaft abgezogen, bei sind sie abfragbar
borncity.com/blog/2023/08/24/d

#api #duolingo #troyhunt #hibp

Last updated 1 year ago

Jonathan Kamens · @jik
672 followers · 3339 posts · Server federate.social

See, now, shit like this is why I assume at this point that pretty much all of my info is out there. "Protect your PII" is not a viable strategy for avoiding identity theft, fraud, phishing, etc.
I do still search data broker sites and get my data taken down wherever I can, just to minimize harm, but I don't hold any illusions about that being a complete fix.
Lock or freeze your credit reports, people.
@troyhunt

#privacy #infosec #hibp

Last updated 1 year ago

Brett Adams · @brett
15 followers · 28 posts · Server social.ba.id.au

Do you want @haveibeenpwned breaches for all your domains directly in Splunk? Now you can!

Introducing the Have I Been Pwned Domain Search app for Splunk.

splunkbase.splunk.com/app/6996

Very special thanks to @troyhunt for his work on HIBP, releasing the Domain Search API last weekend, and collaborating with me on some additional endpoints and rating limiting.

troyhunt.com/all-new-have-i-be

#hibp #splunk

Last updated 1 year ago

Redhotcyber · @redhotcyber
548 followers · 1614 posts · Server mastodon.bida.im
Marcel SIneM(S)US · @simsus
179 followers · 3305 posts · Server social.tchncs.de
🆘Bill Cole 🇺🇦 · @grumpybozo
188 followers · 11413 posts · Server toad.social

Since I have an Amazon-only email address on that account which has never seen any hints of leakage to non-AMZN entities (including ) I’m not too concerned. I’d bet that those ghost sessions were un-logged-off browser sessions orphaned by cookie-cutting. It’s a bit disconcerting that they wouldn’t show them to me.
(Going now to switch the 2FA from SMS to TOTP)

#hibp #amazon #infosec

Last updated 1 year ago

Philip Gillißen · @guerda
155 followers · 1384 posts · Server ruhr.social

@schenklklopfer @343max ich finde viele Funktionen bei XC auch deutlich besser als bei Keepass(X). Passwort-Schwäche finden, , favicon, Autotype. Die Android App ist nicht soo komfortabel, aber insgesamt gut. Nutze ich seit Jahren und bin sehr zufrieden 👌🏻

#hibp

Last updated 1 year ago

Winni Neessen · @winni
50 followers · 143 posts · Server s.pebcak.de

go-hibp v1.0.6 has just been released, introducing support for NTLM hashes in the PwnedPassAPI (see the announcement by Troy Hunt: s.pebcak.de/@troyhunt@infosec.)

:golang: :gopher:

github.com/wneessen/go-hibp/re

#go #golang #hibp #ntlm

Last updated 2 years ago

Leigh Honeywell · @leigh
5588 followers · 998 posts · Server ottawa.place

I have at least 35 Twitter accounts (lol) because I start a lot of silly projects and only one - my main personal hypatiadotca account - got a @haveibeenpwned notification today about being included in the breach dump 🤔

These accounts are as old as 2009 and as new as Nov 2022 (though I understand that the breach set is from 2021).

#twitterbreach #twitter #security #databreach #haveibeenpwned #hibp

Last updated 2 years ago

Lord Winni Neessen :verified: · @winni
46 followers · 103 posts · Server s.pebcak.de

#birdsite #hibp

Last updated 2 years ago

· @lemming
120 followers · 12 posts · Server infosec.exchange

Funny to see all the breaches added to via its RSS-feed. Latest breach added: from 2019 with 229,037,936 accounts.

This is the feed if you want to follow, too:
feeds.feedburner.com/HaveIBeen

#hibp #deezer

Last updated 2 years ago

Lord Winni Neessen :verified: · @winni
43 followers · 58 posts · Server s.pebcak.de

go-hibp v1.0.5 has just been released, fixing and improving the error handling. :golang: :gopher:

github.com/wneessen/go-hibp/re

#golang #go #hibp

Last updated 2 years ago

Ricardo :verified: · @rmdes
792 followers · 1908 posts · Server mstdn.social

This is really cool, I was looking for exactly this, searching offline!

Has your password been pwned? Or, how I almost failed to search a 37 GB text file in under 1 millisecond (in Python) - death and gravity
death.andgravity.com/pwned

#InfoSec #hibp

Last updated 2 years ago

Verfassungklage · @Verfassungklage
1249 followers · 50765 posts · Server mastodon.social

:

Warum , wenn eine -E-Mail reicht?

Kriminelle verlangen per E-Mail Lösegeld für einen angeblichen Hack des Unternehmensservers. Auch Troy Hunt von hat ein solches Schreiben erhalten. ...

golem.de/news/kriminalitaet-wa

#kriminalitat #ransomware #erpresser #hibp

Last updated 2 years ago

Verfassungklage · @Verfassungklage
1607 followers · 51598 posts · Server mastodon.social

:

Warum , wenn eine -E-Mail reicht?

Kriminelle verlangen per E-Mail Lösegeld für einen angeblichen Hack des Unternehmensservers. Auch Troy Hunt von hat ein solches Schreiben erhalten. ...

golem.de/news/kriminalitaet-wa

#kriminalitat #ransomware #erpresser #hibp

Last updated 2 years ago

SoniaCuff · @SoniaCuff
220 followers · 119 posts · Server infosec.exchange

The Have I Been Pwned API now has different rate limits & billing. I'll let Troy explain it: troyhunt.com/the-have-i-been-p

#security #hibp #identity #databreach

Last updated 2 years ago

ITSEC News · @itsecbot
856 followers · 32557 posts · Server schleuss.online
ITSEC News · @itsecbot
856 followers · 32557 posts · Server schleuss.online

“Have I Been Pwned” breach site partners with… the FBI! - If your password gets stolen as part of a data breach, you'll probably be told. But what ... nakedsecurity.sophos.com/2021/ &order

#fbi #hibp #pwned #privacy #password #law #databreach #haveibeenpwned

Last updated 3 years ago

Scimmia di Mare :unverified: · @Madmonkey
1216 followers · 4934 posts · Server mastodon.uno

@informapirata sicuri che ci sia su ?

#hibp

Last updated 4 years ago

· @bojkotiMalbona
111 followers · 1137 posts · Server infosec.exchange

@MaSven
api.pwnedpasswords.com is a site. It wouldn't make any sense to do the check on a new pw.

CloudFlare sees *unhashed* passwords because the hashing is done on the server side. The passwords are not in-the-clear, but CF still sees them of course b/c CF is where the tunnel terminates. It's CF's tunnel & CF's SSL keys.

@infosechandbook@chaos.social

#cloudflare #hibp

Last updated 4 years ago