Log in

View Full Version : Have I been Pwned - check your email address



Mark Grant
24-01-2016, 18:12
Another data breach alert received today so I thought I would share the link.

https://haveibeenpwned.com/

screen grab of some previous results of mine from one of the email address I use for online buying and has been used on some forums.

http://i.imgur.com/QrN7TFR.jpg

Shows the importance of having a separate 'clean' email address just for really important stuff such as banking etc that is never used on a forum or to buy anything online with.

Audio Advent
24-01-2016, 21:12
:thumbsup: Yep indeed.. I also use an online, virtual credit card for some online transactions too (basically you get a picture of a generated card which is real on the virtual card company's system and in the banking system but you pre-load it as and when you need it, no credit, no access to your bank accounts..).

Downside is I often forget email address and passwords because I've not used them in months and months..

Audio Advent
24-01-2016, 21:16
Hmm.... just checked. A really old address I still use is the only one to come up with something, but it talks about a site I've never heard of or ever used (a gaming fan site). Very strange! Perhaps my email address has been plucked from something else to start an account with false details.

struth
24-01-2016, 21:19
I have a email associated with adobe, but its not been accessed on adobe for many years. It is one I still use though..... may have to get a new one I suppose.:doh:

Old George
25-01-2016, 19:48
All clear.......For now. Thanks for the heads up.:)

struth
25-01-2016, 20:07
Yes I am clear too

Marco
25-01-2016, 20:10
Is that why you're still using that cream? :eyebrows:

Marco.

struth
25-01-2016, 20:15
Lol! Yessiree, gotten use the cream

Spectral Morn
25-01-2016, 20:34
Not involved in any of the named sites, which had security breaches. Thing is I don't trust these 'issue' search sites either so I am not putting my details into it.

Audio Advent
25-01-2016, 22:54
Not involved in any of the named sites, which had security breaches. Thing is I don't trust these 'issue' search sites either so I am not putting my details into it.

Haha... those were my initial thoughts too. I had to do a search for it first to see what people were saying about the site before I tried it.

Macca
26-01-2016, 08:49
It's not the 'You've been pwned' message you need to be concerned about. When you see 'All your base are now belong to us' - that's when you need to worry...

Mark Grant
26-01-2016, 21:28
Not involved in any of the named sites, which had security breaches. Thing is I don't trust these 'issue' search sites either so I am not putting my details into it.

Always good to be careful although I wouldn't post anything that was dodgy in any way.

The site is by Troy Hunt, one of the good guys that makes life harder for hackers.

https://haveibeenpwned.com/About

http://www.troyhunt.com/2016/01/the-impact-of-have-i-been-pwned-on-data.html

By exposing when data has been breached Troy devalues that data dump as people will start changing passwords and email addresses so the data becomes old very quickly and has little value.

Mark Grant
05-05-2017, 17:07
Another really big data breach revealed on that site today, one of my wifes email addresses and passwords is in the list.

https://www.troyhunt.com/password-reuse-credential-stuffing-and-another-1-billion-records-in-have-i-been-pwned/

https://haveibeenpwned.com/

Dynamics
06-05-2017, 19:19
It came up for me that I've been hacked from LinkedIn due to a security breach. But to be honest I think this is always going to happen and someone somewhere in the government probably knows what I'm writing anyway. So I don't really care and give it a moments thought if someone gets their kicks off of this. My stuff is probably way too boring anyway.

AlexM
17-05-2017, 15:09
The real security issue is that it is in human nature to re-use passwords. So if you say, used the same email address for your amazon account, ebay etc, tesco, electronic banking etc. with the same password, someone can 'legitimately' access your account by trying to log into other sites with the user id and password that they have from another account. A quick change of delivery address and account email/password combo and you can go shopping.

Worse still, sometime more than just an email address and password are on these lists - your real name, address, date of birth etc can also be misused to sign you up to services, pass credit checks etc.

Its all a bit of a minefield, but what you should think about using is a password manager like Roboform 8: it acts as a safe repositiory storing all login details securely, and it allows generation of random, hard to guess passwords that are unique to each website, as well as automating the login process. It also replicates between computers, phones etc seamlessly so your passwords are always available to you. Of course, the password store needs to be protected by a difficult to crack password, but it does enable you to use a much more secure method of navigating websites.