Post #1690415
2024-05-20 23:46 UTC
Just realising that HIBP #haveibeenpwned service is no longer any use to me personally.
While I understand that Troy has had increasing costs and is seeking to mitigate these, especially in light of half the Fortune 500 using the service, I think it has left non-corporate enthusiasts like me out in the cold.
I think Troy addresses these risks pretty clearly in his post at https://www.troyhunt.com/welcome-to-the-new-have-i-been-pwned-domain-search-subscription-service/
But for me, with 1 domain and due to:
1) Trying to use a unique email address per site I actually do sign up for, and
2) Fake entries (perhaps typos) where someone has used my address (Troy confirmed he thinks my entry on the AT&T breach is a typo someone else made);
This results in my domain having (currently) 22 addresses across various breaches.
Well beyond the 10 limit of the 'free' tier.
Thus I'm unable now to determine if any new breach is a fake entry or from an address I did create (potentially also indicating the source of any leak/breach).
Interested in the thoughts of others here.
Replies (1)
-
@andrewg@mastodon.ie 2024-05-21 06:09
@pg@infosec.exchange yeah, I used to do #1 a lot, but got out of the habit. I didn’t get as much utility out of it that I felt justified the hassle, even with a password manager. So hibp still works for me, but I can easily see why you’re frustrated… 😖