SIGforum.com    Main Page  Hop To Forum Categories  The Lounge    Is “HaveIBeenPwned.com” legit?
Go
New
Find
Notify
Tools
Reply
  
Is “HaveIBeenPwned.com” legit? Login/Join 
Baroque Bloke
Picture of Pipe Smoker
posted
It was recommended in this Dailymail article which reports a massive exposure of SSNs:

https://mol.im/a/15591707



Serious about crackers.
 
Posts: 11302 | Location: San Diego | Registered: July 26, 2014Reply With QuoteReport This Post
If you see me running
try to keep up
Picture of mrvmax
posted Hide Post
Not sure if it is legit but if there is anyone who has never been part of a “security breech” you will eventually be part of one.
 
Posts: 5082 | Location: Friendswood Texas | Registered: August 24, 2007Reply With QuoteReport This Post
Oriental Redneck
Picture of 12131
posted Hide Post
 
Posts: 30984 | Location: TEXAS | Registered: September 04, 2008Reply With QuoteReport This Post
Optimistic Cynic
Picture of architect
posted Hide Post
Any entity that maintains a database of compromised credentials has to be the most desirable target there can be for those who wish to profit from this information. I sure hope the maintainers of the site referenced in the OP is aware of this and has extremely strong measures in place to protect themselves and those they are trying to "help."

Additionally, I suspect the site is merely a front offering a "first one is free" come on for expensive "in-depth services."
 
Posts: 7927 | Location: NoVA | Registered: July 22, 2009Reply With QuoteReport This Post
Fighting the good fight
Picture of RogueJSK
posted Hide Post
quote:
Originally posted by Pipe Smoker:
Is “HaveIBeenPwned.com” legit?


Yes, it's a well-known and legitimate security website.

quote:
Originally posted by architect:
Any entity that maintains a database of compromised credentials has to be the most desirable target there can be for those who wish to profit from this information. I sure hope the maintainers of the site referenced in the OP is aware of this and has extremely strong measures in place to protect themselves and those they are trying to "help."

Additionally, I suspect the site is merely a front offering a "first one is free" come on for expensive "in-depth services."


Regarding the "keeping a database of compromised credentials is dangerous" argument, they get these lists by trolling the dark web and backchannel hacking forums/discords to find publicly available compromised credentials that have been published there, usually in large data dumps of millions/billions of credentials at a time.

They then sort through the data and notify the compromised folks of their inclusion as a public service.

So any info they'd have on hand is already previously compromised, and is already out there and available for bad guys to use.

Therefore someone hacking into them just to get the same publicly available info would be a lot more work for no additional gain, over simply getting it off the dark web or hacking forums/discords like any other bad actor would.

So that argument doesn't hold water.


And as for the "first one's free/they're trying to sell you something" argument, they don't ever charge for personal use, and don't sell services to users.

The only time they charge is for large domain owners and security researchers who want to run huge batches of automated queries through their data archive.

So zero charge ever for you and me searching one credential at a time. But a few hundred bucks a month to someone like Google or Microsoft who wants to run 10,000 searches a second through it.
 
Posts: 35208 | Location: Northwest Arkansas | Registered: January 06, 2008Reply With QuoteReport This Post
Member
Picture of uvahawk
posted Hide Post
Nice to know when your data has been compromised, and the company hacked has not bothered to share with those affected. For me that is the value of “HaveIBeenPwned.com”
 
Posts: 397 | Location: Low Country, South Carolina | Registered: November 28, 2004Reply With QuoteReport This Post
Member
posted Hide Post
YES it is legitimate and referenced many times by legitimate security people and websites. God Bless Smile


"Always legally conceal carry. At the right place and time, one person can make a positive difference."
 
Posts: 3219 | Location: Sector 001 | Registered: October 30, 2009Reply With QuoteReport This Post
Baroque Bloke
Picture of Pipe Smoker
posted Hide Post
^^^^^
Thanks Rogue. I just checked. The report says “Oh no — pwned!”
April 2021 via “Linkedin”.

I deleted my Linkedin account years ago, and saw no problems then (nor since), so I suspect that I’m safe. I’m damned sure that I didn’t provide my SSN or other critical info to Linkedin.



Serious about crackers.
 
Posts: 11302 | Location: San Diego | Registered: July 26, 2014Reply With QuoteReport This Post
A Grateful American
Picture of sigmonkey
posted Hide Post
To see if your social security or any other information such as financial accounts, credit cards PIN codes, passwords and more, have been compromised, please go to following site and enter all that information and we will search the entire internet and let you know.

https://YGTBSHM!.com




"the meaning of life, is to give life meaning" Ani Yehudi אני יהודי Le'olam lo shuv לעולם לא עוד
 
Posts: 46420 | Location: Box 1663 Santa Fe, New Mexico | Registered: December 20, 2008Reply With QuoteReport This Post
Shaman
Picture of ScreamingCockatoo
posted Hide Post
quote:
Originally posted by Pipe Smoker:
It was recommended in this Dailymail article which reports a massive exposure of SSNs:

https://mol.im/a/15591707



I got the letter in the mail.
Only AFTER I've been dealing with hackers since December.
I had to lock down all of my accounts.

They are STILL trying to get into my e-mail and such.
ANNNNND because it was through work, they actually reset my work financial account and tried to have my check direct deposited.
(yes I have ALL of their information, even their address now.)

All this data mining company did was offer me FREE MONITORING!
So they're absolutely held UNACCOUNTABLE for my information.


HAve I mentioned how much I hate people?





He who fights with monsters might take care lest he thereby become a monster.
 
Posts: 40417 | Location: Atop the cockatoo tree | Registered: July 27, 2002Reply With QuoteReport This Post
Member
posted Hide Post
With all the data breaches at credit reporting agencies and national healthcare providers/systems, one should assume that their SSAN, DOB and other statistics are "out there". Easy way to combat most of this is to keep your credit frozen with the 4 national credit reporting agencies, avoid common use or duplicate passwords, 2-3x authentication factors, etc. It can sometimes be a PIA, but it sure beats the alternative.
 
Posts: 5302 | Location: NH | Registered: April 20, 2010Reply With QuoteReport This Post
Peace through
superior firepower
Picture of parabellum
posted Hide Post
My only objection to that site is its stupid name.
 
Posts: 114165 | Registered: January 20, 2000Reply With QuoteReport This Post
Shaman
Picture of ScreamingCockatoo
posted Hide Post
These assholes used my SSN and CALLED the pay company to get my account changed.
I was in with financials when they actually changed my password and bannkking information right there in front of her.
Had her lock my account.
They actually had the pay company CALL to try and unlock the account.
Idiots left a traceable IP and banking information.
Bancorp Bank. And they're in Bronx New York.

Para isn't gonna let me DOX them here.





He who fights with monsters might take care lest he thereby become a monster.
 
Posts: 40417 | Location: Atop the cockatoo tree | Registered: July 27, 2002Reply With QuoteReport This Post
Member
Picture of 4MUL8R
posted Hide Post
I find my Allstate identity protection service helpful, in place of my own feeble attempts to monitor. I was given this service as a corporate benefit, and keep it now in retirement.

I also practice password control with the Apple passwords app. Easy to change passwords and also create passkeys.


-------
Trying to simplify my life...
 
Posts: 6114 | Location: Commonwealth of Virginia | Registered: January 15, 2007Reply With QuoteReport This Post
No More
Mr. Nice Guy
posted Hide Post
quote:
Originally posted by ScreamingCockatoo:

Idiots left a traceable IP and banking information.


I hope you can get some criminal charges placed.

My father had a similar situation. The perp phoned Fidelity and pretended to be him. They had his info and convinced Fidelity to empty his brokerage account and send a physical check to a physical address. Even with the perps voice on tape and a specific address, no law enforcement was interested in anything other than filing a report.
 
Posts: 11172 | Location: On the mountain off the grid | Registered: February 25, 2002Reply With QuoteReport This Post
Shaman
Picture of ScreamingCockatoo
posted Hide Post
quote:
Originally posted by 4MUL8R:
I find my Allstate identity protection service helpful, in place of my own feeble attempts to monitor. I was given this service as a corporate benefit, and keep it now in retirement.

I also practice password control with the Apple passwords app. Easy to change passwords and also create passkeys.



The company I work for gave me the Allstate plan with a fiduciary.





He who fights with monsters might take care lest he thereby become a monster.
 
Posts: 40417 | Location: Atop the cockatoo tree | Registered: July 27, 2002Reply With QuoteReport This Post
Shaman
Picture of ScreamingCockatoo
posted Hide Post
quote:
Originally posted by Fly-Sig:
quote:
Originally posted by ScreamingCockatoo:

Idiots left a traceable IP and banking information.


I hope you can get some criminal charges placed.

My father had a similar situation. The perp phoned Fidelity and pretended to be him. They had his info and convinced Fidelity to empty his brokerage account and send a physical check to a physical address. Even with the perps voice on tape and a specific address, no law enforcement was interested in anything other than filing a report.



Oh I had to call Merril immediately as soon as I got an alert that I was trying to change my password.
Had them lock all access online and I have to give a PIN to access at a branch.(BoA)

I gave all the information to the banks. I suspect they really don't care.





He who fights with monsters might take care lest he thereby become a monster.
 
Posts: 40417 | Location: Atop the cockatoo tree | Registered: July 27, 2002Reply With QuoteReport This Post
אַרְיֵה
Picture of V-Tail
posted Hide Post
quote:
Originally posted by ScreamingCockatoo:

Idiots left a traceable IP and banking information.
Bancorp Bank. And they're in Bronx New York.

Para isn't gonna let me DOX them here.





הרחפת שלי מלאה בצלופחים
 
Posts: 33404 | Location: Central Florida, Orlando area | Registered: January 03, 2010Reply With QuoteReport This Post
  Powered by Social Strata  
 

SIGforum.com    Main Page  Hop To Forum Categories  The Lounge    Is “HaveIBeenPwned.com” legit?

© SIGforum 2026