Author Topic: PSA: Use HaveIBeenPwnd.com to see if your email/account was ever compromised.  (Read 2306 times)

neo von retorch

  • Magnum Stache
  • ******
  • Posts: 4940
  • Location: SE PA
    • Fi@retorch - personal finance tracking
And change your password. And use a password manager.

Visit Check if you have an account that has been compromised in a data breach

Password reuse, credential stuffing and another billion records in Have I been pwned

I was actually pretty bad about all this until recently. (Now I'm only mediocre.) Anyway, I use unique email addresses, and 14 of them have shown up as compromised. Places like LinkedIn, Adobe and DropBox.

neo von retorch

  • Magnum Stache
  • ******
  • Posts: 4940
  • Location: SE PA
    • Fi@retorch - personal finance tracking
Definitely a good service.  One thing about the data you get from them, though.  I'm sure you know this but others might not.  If your email address shows up in a list, that doesn't mean your actual email account has been compromised.  If it says that your email was found on for instance a DropBox breach, the password you used for your DropBox account is the one that's likely compromised, so that's the one you need to change.  If you're using that password for multiple accounts, change all of them, preferably to unique passwords.  Password managers like Dashlane and 1Password make doing this VERY easy.

Great points! For many people, they have one email address. If your email address/password combination was compromised at any one site, any other site that uses the same combination (which could include your email account!) could be compromised via "credential stuffing" so keep that in mind.
« Last Edit: May 05, 2017, 07:50:05 AM by neo von retorch »