General
187 results found
-
Catch all
Implement support for catch all email addresses. I use a different mail address per website I register to. Its all on the same domain that is configured to support catch all e-mail. In theory I could use an UUID email adres per website.
In order to proof you are the owner you could send a verification mail to a random mailadres for the given domain.
3 votesThis feature already exists, it’s under the “Domain search” link in the nav.
-
1 vote
I’m presently looking for the data, will certainly load it once it turns up.
Closing this out as I keep User Voice for feature suggestions.
-
Allow notifications for an entire domain or allow a way to pull the domain report without having to verify every time.
We have access to a private feed of password dumps that we query every day automatically so we can proactively notify our users of account compromises. It would be really cool if we could also query haveibeenpwned in a similar fashion without having to manually verify domain ownership each time. This would allow us to automate the retrieval of the report.
Another option would be to allow people to sign-up for domain wide notifications similar to how you allow people to sign-up for individual account notifications.
Either way, the goal is to automatically receive or retrieve the information so we…
1 vote -
Charge for the service
Good service but I think you need $ to improve it.
A user could be charged a small amount, around €1, for the release of information related to a security breach.
The basic account could be free but the user would have to pay for advanced services.1 voteI’m quite clear at this time that I don’t want to charge people for a service that does them good, nor do I want to put them at more risk by making data beyond their email address accessible over the web.
-
Notify email owner privately to limit malicious intents
I like the fact that I get to know if my email is pwned in any of the latest breaches (so opting out is not really an option), but I can see a malicious intent here as well.
Say a hacker needs to get access to my email account, then the first thing to try is your service to know if my password exists in any of the known breaches, even though I might change it but some users won't or it may be easily guessable.
My idea is, when the user enters their email address, send the results by…
41 votesI left this open for quite a while as I gave it thought, but ultimately concluded it’s not a viable approach. Here’s my thoughts in full: https://www.troyhunt.com/the-ethics-of-running-a-data-breach-search-service/
-
Esso Canada called me regarding their speedpass rewards program being compromised. Not sure if it's a one-off or more than that.
customer service said that someone accessed my account, changed the email address on file, then proceeded to order e-gift cards.
Can you check into it if possible?
1 voteNot an idea
-
Provide an email address to send you PROBLEMS with your confirmation system
I tried to set up a notification to my email, but the confirmation email you sent came in without a link (twice). I would have liked to notify you privately, but can't find any email on your site to write to privately! I use webmail on a HostGator hosted domain that I own, but the email comes in with text and a big blue banner where the link should be, but no link.
0 votesSupport question, not an idea
-
Incomplete Data
One of my several email id has been part in one of the data leak but searching here shows that it is not. This shows there is some discrepancy in data you refer to. I can not reveal much publicly here but you can reach out to me and i shall share more details.
1 voteSupport query, not a suggestion
-
Include email addresses (or some info) for domain notifications
If you're doing a domain notification (notifying of any info for your domain that becomes compromised), you'd like to relay concerns to your users when those alerts come up. Right now, we're just getting a number of accounts, rather than the actual specifics. Even listing email addresses would help.
1 vote -
Include leaked password
You very kindly just sent me an email that my email address and unsalted password were included in the 2012 LinkedIn breach.
I can't remember which password I was using in 2012, and hence don't know which other accounts need a password change. Could you send the leaked hash (or otherwise, depending on the breach) to the effected email?
3 votesThis presents too many risks, more info here: https://www.troyhunt.com/here-are-all-the-reasons-i-dont-make-passwords-available-via-have-i-been-pwned/
-
Ok, so I've been pwned, now what?
Is there a means of fixing the issue?
Can I get my name off the pwned list? (without opting out)
Would it help to contact the pwned website(s) with my data?
Thanks
1 vote -
Stop sending bogus emails
I've had emails saying that both my tumblr and MySpace accounts have been breached, however I don't have accounts on either system.
1 vote -
acknowledge option
Hi,
It will be nice to have an "acknowledge" option if i subscribe - so when i see list of sites/accounts i changed my password too i would be able to acknowledge and then see only new threats as redthanks,
1 voteHIBP is not intended to be a personal checklist, rather a historical record of data breaches.
-
Add URL for a certain paste
Using the crowd, I have finally solved the mystery which database a certain paste represents: http://security.stackexchange.com/questions/108191/what-can-i-do-if-i-discover-that-my-password-hash-has-been-leaked-in-pastebin
Can I/Could you add that information?
1 votePastes are retrieved “as is”. There’s a large volume that flows into HIBP and I don’t modify any metadata about them, I merely represent the information they contained.
-
Add wpengine.com breach
There was a breach on wpengine.com, maybe data about accounts will be available somewhere
https://wpengine.com/support/infosec/1 voteI’m not aware of this breach being in the public domain but if you happen to have it, contact me privately. Closing this out to keep the UserVoice for feature ideas.
-
RSS feeds not working/validating
Thunderbird refuses to open either your breaches or pastes RSS feeds, claiming failed validation. The w3c feed validator fails both: https://validator.w3.org/feed/
Whether they are broken or not is beyond my experience :-)1 vote -
Provide a open sourced version of the PB scraper for users to run at home and tinker with.
Title explains it.
3 votesHIBP gets the paste feed from Dumpmon which is already open-sourced here: https://github.com/jordan-wright/dumpmon
-
Unsubscribe button please
This service is awesome and user will be warned if they are pwned.
But the registration confirmation email says "...and you can unsubscribe at any time if you don't want the notifications."
Please, make an unsubscribe button. I can't find any unsubscribe button or form on the website or in the email.
Thanks.1 voteFeature already exists
-
Add a captcha
Because people often use the same user and password combination on multiple sites. If you can search here if you have an account on multiple sites, others can too. If you can slow down automatic search, abusers can be scared away
3 votesA CAPTCHA implementation poses an unacceptable usability barrier whilst providing little practical benefit and would entirely break the API implementation.
-
either allow use of email from domain registration, or don't claim to
The domain registration page says "Verifying by email is the fastest way to confirm ownership of the domain. You can either verify using an email address on the domain registration record or by using one of several pre-defined addresses for the domain." However, in fact I cannot find any way to use the email address actually on my domain registration record (paleo.org), as it is not one of the four standard addresses listed.
1 voteSupport query rather than an idea (and resolved now anyway).
- Don't see your idea?