Hacker News new | past | comments | ask | show | jobs | submit login

If you don't know who is Troy Hunt, then one thing to do right now is to signup for his great service: https://haveibeenpwned.com/

in essence, everytime(+) some massive break occurs, and your e-mail (and probably password) is among them after reaching "darknet" (meaning black market), you will get from haveibeenpwned an e-mail, urging you to some action (password change, account closure/change etc).

(+) Troy amassed over the years huge db of past breakins (so you can check your email presence also in past events) and with current respect/reputation he gots access to new ones pretty fast, informing you instantly in most cases.

Highly recommended.




> after reaching "darknet" (meaning black market)

> with current respect/reputation he gets access to new ones pretty fast, informing you instantly in most cases

So he has the respect of (street cred with?) the dark net/black market folks and that's how he gets them instantly? Or I suspect you meant to say something slightly different?


These lists get 'traded' amongst security professionals a lot. Quite a few of them will send Troy a copy to load in to HIBP.


I don't know how he obtains the data, but in [1] he makes a point of never having paid for it.

> I've also never paid for data nor traded any of the breaches I've obtained.

[1] https://www.troyhunt.com/thoughts-on-the-leakedsource-take-d...


You can sign up your entire domain if you control the postmaster@ address.


If you have a Google hosted domain you cannot have this as an alias... but you can create a Group with this alias and add yourself to that.


A few other email addresses, including those on the WHOIS record, can be used. You can also verify using a meta tag, file upload, or DNS record.


This is a great service! And according to it my account has been pwned(what does this mean?)




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: