Hacker News new | past | comments | ask | show | jobs | submit login
[flagged]
gt565k 5 months ago | hide | past | favorite



I have a custom domain with a site-specific email. No 2 sites have the same email address. I have not seen any activity using that 'hacker-news' account. Not saying your experience isn't accurate, providing one additional datapoint for analysis.


HN passwords have been bcrypted (at least) since 2013.


I think that what the user implies here is that the email address (rather than the password) was leaked. Maybe the password was just weak. But there’s not enough evidence.

But the account is from Jan 2013. Maybe not bcrypt yet. If password was never changed, is there a chance that the used algorithm was weak and crackable, and so in the event of a leak this could actually be a problem?


I'd say the possibility of your own computer having a virus infection, or your login credentials leaking some other way, is far more likely than assuming "HN might be hacked."


Well.... What kind of password did you have? Was is complex and extremely difficult to guess .... Or?


>Got an email security alert from gmail

I'd make sure that it was a legitimate alert by going to (https://myaccount.google.com/security) because there's tons of fake alerts going around, a lot looking quite legitimate. Was the first thing that almost caught me in years.


Is the email listed on https://haveibeenpwned.com/ ?




Join us for AI Startup School this June 16-17 in San Francisco!

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: