Hacker News new | past | comments | ask | show | jobs | submit login

Anyone got a link to where one might check for the presence of their own email in this list?




Is it ironic that to check if my email is vulnerable i'm typing it in to a website that i'm not sure whether to trust?


My thought exactly... I did not choose to do so =P


Is there a better way than typing my email address into a site of questionable integrity?


It's not too hard to find a link to the .tar.gz on Mega.co.nz, if you don't mind burning 9 GB of disk space. It's a plain text file, so you can just grep it.

The consequences of this release are going to be felt for a long time. It's the worst thing I've ever seen happen on the Internet, and I've been around a while.


I suspect as "the worst thing ever on the internet" it'll do wonders for sales/downloads of 1Password/Keypass/Lastpass/whatever, and bring awareness of the need, as well as the ability to easily have separate strong passwords for _every_ site/account/login to "the general public" - which'll be a big win for internet security generally (at the expense of everybody who loses out from exposed and re-used credentials).

I have a possibly-not-too-paranoid suspicion that "the worst thing resulting from the 2013 Adobe compromise" may yet be to be revealed. People have joked for years about the "Adobe updater virus" – but what's protecting everybody who's now so familiar with weekly or monthly Acrobat/Flash/Air update boxes popping up asking for admin credentials? If they lost the Photoshop source code, is it even vaguely plausible to suggest they couldn't possibly have also lost root on the update servers, or their SSL private keys, or admin access to the dns zonefiles, or the adobe.com registrar credentials, or any of the other steps in the chain that'd allow attackers to push a malicious Adobe update?


I will probably download the tarball to check, but it would be swell if that "check your email address" form allowed pattern matching, so I could just grep for a substring instead of typing in my whole address.

Edit: just for laughs: warnock@adobe.com was found. You need to change your passwords now

I wonder what his password is. I guess we'll find out eventually.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: