General
204 results found
-
Can we have option to add email address in verification
It provides predefined email addresses. Can a previously verified user add another user email for verification. Also the verification process does not provide details if the email was sent successfully ( In my case it says successful but I am not receiving verification email)
1 voteAlready implemented
-
How to check if someone with complete access to my company server and all email ID's, has been stealing information?
I've recently found out that my IT person from my company has been stealing information from us. He has complete access to it's domain and server. Do you have any advice on how I can see what kind of information he has taken?
If you have any recommendations on how to find the information on his personal email ID's, that would be very helpful. Thanks1 voteThis is not a feature suggestion for HIBP
-
Recover latest pastes RSS feed
The latest pastes RSS feed is empty
1 voteI’ll be writing about this change in the next day, stay tuned to troyhunt.com for more
-
what is this someone help me
Oh no — pwned!
Pwned on 4 breached sites and found 1 paste (subscribe to search sensitive breaches)1 voteThis site is for feature requests so I’m closing this “idea” out.
See the information below the message you posted for details on which sites your email address has appeared breached on.
-
provide Solutions
Provide Solutions on "How To" reverse the process of compromised email address and passwords.
1 voteYou cannot reverse an email address and password having been exposed, it is an immutable historic event.
-
Only distribute unique sha1 values
The files version 1, update 1 and update 2 contains 320,3355,236 SHA1 values but only 320,294,464 are unique the difference are 40,772 values
1 votePlease use UserVoice for feature requests.
-
www.socialengineforum.com (1 Jan '01): http://www.socialengineforum.com/dump.sql
the listed date - "(1 Jan '01)" is, shall we say, an out-of-bounds error. Site didn't exist that long ago!
1 voteIf the data is no longer there, I can’t tell you anything more about it as I don’t save pastes.
-
Removing cloudflare on api
Cloudflare antibot on your api doesn't make any sense, i have a python discord bot with your api implemented and because of cloudflare i cant use the api anymore and i have quite a few users who use the function.
1 voteCloudflare is absolutely essential for protecting the API from abuse. The only time it should get in the way of legitimate use is if you consistently exceed the rate limit and cause a 24 hour JavaScript challenge to implemented against the offending IP address.
-
1 vote
This UserVoice is for suggesting new ideas. If you have an idea you’ve been trying to get in touch with me about and haven’t been able to reach me, please detail it as a new item here. Do read the other ideas here too as well as the HIBP tag on my blog in case it’s already covered there: https://www.troyhunt.com/tag/have-i-been-pwned-3f/
-
To use hashed email address as part of the query instead of HTML encoded
I don't know if this is already available, but I feel it will be a better idea.
1 voteIt provides next to no security (I already have billions of addresses I could use to crack it) and it would require an entire copy of the system hence doubling up on all the storage costs.
-
Not very smart features
I've changed my password but my mail remain in the list. When my account will be "pwned" again, I will not know about it.
1 voteHIBP is a reflection of which emails were breached in which systems and is not designed to track what changes are made to an account post-breach.
-
explain in the FAQ why a mail address (mine!) appears as hacked in your tool, but the associated password is not listed as hacked?
Does it mean that the e-mail adress was hacked, but that the associated password was not decrypted? If not, why the password is not found in your database? Thanks.
1 voteHIBP does not store passwords.
-
Bring back sorted hashes
I used to lookup password hashes by a binary search in the sorted password list (iterating over the initial database and the 2 updates).
With the new database 2.0 this is no longer possible (unless I sort the downloaded hashes).
Please bring back the sorted hashes.
I do not care for the counts that have been added - perhaps another file with sorted hashes and without counts (to somewhat reduce the file size) could be offered for download?
1 voteI’m trying to avoid having multiple versions of the same thing, I suggest that if a different order is important you just do a one-off reordering of the file.
-
What is LogoType?
Can you describe what the intended use of the LogoType field in the Breach object is? I can't find anything in the API docs that describes the field. I know what SVG and JPG are, but to what do they refer? Do you have (or plan to have) an API that will return a logo for the name of a breach? I can see from the source of your web pages that you have that data in the content folder
1 voteThis is intentionally undocumented and will be replaced by a formally documented alternative in the future.
-
1 vote
There was no Twitter breach, they inadvertently logged passwords to an internal system and there’s no evidence they were ever obtained by an unauthorised party.
-
I'm getting an "Oh no catastrophic failure" message repeatedly for one password in particular - I'd like to understand what that means.
I'd like to understand what the "Oh no catastrophic failure" message actually means.
1 voteInsufficient information to reproduce
-
Mark ArmorGames as confirmed pwned
I use unique email address per subscriber, and I suddenly started receiving spam on the email I used to signup for armorgames.
They are not trustworthy. -- this is not an idea, but saw that you have listed them as unconfirmed, I can confirmed my data was leaked from their site --
1 voteIt’s the combination or Armor Games and Coupon Mom together which means this breach is unverified; I can’t emphatically say which addresses are from which service.
-
when I enter capital letter in domain name it is not working. Please make it case sensitive
when I enter capital letter in domain name it is not working. Please make it case sensitive
1 voteDomain searches definitely aren’t case sensitive, add specific details if you believe it’s not working with a particular name.
-
Domain Verification - Not received after several tries.
Verification token sent An email containing a verification token has been sent off to the address you chose, just copy................
Kindly help for fix.
For your note:
1. Domain not blocked in mail server
2. haveibeenpwned domain - whitelisted
3. message header not found in mail server inbound logs1 voteUser voice is for submitting new ideas so I’m closing this one out. Make sure your mail server is allowing messages from noreply@haveibeenpwned.com
-
Question: any way to opt-out a closed e-mail account address?
I asked to opt-out an e-mail address, but since I closed the e-mail account (it's already a year since) I find difficulty in confirming the verification e-mail. Any alternative thing I can do to try to block the e-mail address from showing in this site? Thanks!
1 vote
- Don't see your idea?