5 ms·
I don't know about you, but I can't bring myself to punch my ID into a random website.
by sordidfellow 12y ago
I don't know about you, but I can't bring myself to punch my ID into a random website.
- drivingmenuts 12y agoI feel like I will have been pwnd. Maybe that's the next website to build: willihavebeenpwnd.com and then whenwillibepwnd.com
- jgeorge 12y agoIt's time to break out Dr. Dan Streetmentioner's new Guide to Future Domain Names.
- mseebach 12y agoUnless you use different usernames/email addresses for all the websites you sign up for, this website isn't any more or less random than any of the hundreds of websites you've punched your ID into (and of which some, more likely than not, has been compromised).
- sprash 12y agoIf you fear your credit card info has been stolen, enter it here and you can find out for free. Avoiding fraud has never been easier!
- kazinator 12y agoNot the same thing at all because your e-mail address isn't a security token. e-mail addresses aren't secret; you give them away all the time. Would you put your credit card info on a business card and give it to people you meet?
- gizmo686 12y ago>Would you put your credit card info on a business card and give it to people you meet? Of course not, I just hand it to the minimum wage cashier, say it over the phone whenever I am ordering delivery, and type it into online stores.
- rwallace 12y agoIt only asks for your e-mail address, not your password or any other secret information.
- kevinoconnor7 12y agoThey should really accept a hash of your email/username to lookup. Then we can an idea of if we've been pwned without giving additional information if we haven't been.
- jdludlow 12y agoI'm not sure how that would help. They would have to generate a matching hash on their end, giving them a lookup table to work backwards from hash to email address. Now if they wanted to supply a list of hashes to the public, then you could check your own without knowing any of the other addresses used to generate the remaining hashes.
- kevinoconnor7 12y agoYes, but they would already have your e-mail address anyway. Lookup by hash precludes the case where you're giving them information they didn't already have.
- bitJericho 12y agoBut you're still feeding into the "this is a good working address" and "this is a security newb" email lists.
- jdludlow 12y agoTrue. I was more referring to it being a confirmation that this is an email address that anyone cares about. If I wanted to be truly malicious I'd have my online checker return a "Nope, you're all good" and then add that email address to the short list of accounts to go after.
- wglb 12y agoBut the point is that your email is possibly already out there, circulating around. Would you rather not know?
- superuser2 12y agoThe fact that your username exists is almost always public information, and all you'd be disclosing. That's why we have passwords.