news.volyx.in

Two billion email addresses were exposed (troyhunt.com)

634 points by esnard · 260 days ago · 449 comments on HN

Article summary

A collection of 2 billion email addresses and 1.3 billion unique passwords has been indexed by Have I Been Pwned, with 625 million of the passwords never seen before. The data was obtained from various locations where cybercriminals had published it, and it is the largest corpus of data processed by Have I Been Pwned to date. The data includes email addresses and passwords from numerous sources, including malware and credential stuffing lists. The indexing of this data aims to notify victims and render the exposed credentials useless.

Main themes

  • Data breaches
  • Password security
  • Credential stuffing
  • Cybercrime
  • Data indexing
  • Notification of victims

What commenters say

  • A standard way to update passwords from password managers automatically is still lacking, which would help mitigate the impact of data breaches.
  • Some argue that passkeys could be a solution to password leaks, but others find them to be an opaque and impractical solution.
  • The lack of backwards compatibility with passkeys is a significant conundrum, as it would be more practical to enable passkeys as a replacement for passwords.
  • Some commenters feel that Have I Been Pwned's limitation on free searches for domains with over 10 breached addresses is frustrating and restrictive.
  • Others argue that having unique email addresses for each website is not effective in preventing data leaks, as the email address itself is not the secret, but rather the password.
  • There is a disagreement on whether knowing which specific email address was compromised is useful, with some arguing it is essential to change passwords, while others think it is not necessary.
  • Some commenters point out that even with strong passwords, the logistics pipeline of cybercrime can still make use of harvested email addresses, increasing their value by associating them with active accounts.
  • The usefulness of Have I Been Pwned is limited for individuals who use the same email address across multiple websites, as it only notifies them of a breach without specifying which site or password was compromised.