Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I mean hibp is run by Tory hunt who has a good record as security researcher. So yes it's a centralised place but all it does is aggregate breaches and makes them searchable (to a degree, and not in a way that is useful for nefarious users). The breaches are not shared but those breaches are out there and nefarious users don't need hibp to get access to this data. It is really only useful to end users who want to see if they are at risk.


We don't know what that server is running. If it keeps a log of all the queries then it has a pretty nice list of emails from people that might make good targets.


Go read up about HIBP and Troy Hunt. It doesn't log requests, it tries to make it as difficult as possible for nefarious users to get any data from it. All the emails it checks are already included in public breaches which are available in the wild.

You seem to be throwing shade at a service and person you haven't researched and all behind a new account. Very brave of you.


I honestly don't care who this guy is. A centralised server providing this service is a problem. It's not like he is using some magic decentralised thing to run queries so we have mathematical proof nobody can aggregate data. No, it's a server he alone has root running whatever software.

The notion itself of revealing info about you to a 3rd party in order to verify that more info hasn't been leaked seems... conflictual at some level.

Your account presumably isn't new. Are you any braver?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: