Skip to content

General

59 results found

  1. Figure out a better pricing model for individuals

    I am an individual with my own email domain. I give out different addresses to every site. I used to be able to use you to find out which ones are loose, but you are treating me like a company. I cant afford $137/month! Yet my domain has 58 compromised emails. WHich ones?

    1 vote
    Vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
    You have left! (?) (thinking…)
    1 comment  ·  Admin →

    There's no way for us to know in any automated fashion whether a domain belongs to a corporation or an individual. If you submit a ticket with the details, we can take a look and see what we can do manually: https://support.haveibeenpwned.com/hc/en-au/requests/new

  2. Put Resellers in their own data domain for Stripe

    I watched your video post the other day and I have a suggestion on how you should approach the “Reseller” issues you needed to address.
    Consider putting them in their own domain now.
    You have “Resellers” and then everything else. Rather than mixing Resellers into your data model, take a stronger approach into separating them into their own data domain.
    That way you can treat the Resellers domain to all of the constraints you need to apply for whatever additional issues that they cause you and not need to consider how those constraints will affect everything else.
    Then you are…

    1 vote
    Vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
    You have left! (?) (thinking…)
    completed  ·  0 comments  ·  Admin →
  3. Do not count adresses found in "LinkedIn Scraped and Faked Data (2023)" for the free domain search

    I have a personal domain but several fake adresses in the "LinkedIn Scraped and Faked Data (2023)" breach and can no longer check if any of my real addresses are in a breach...

    I don't mind if companies have to pay for your service, but I think it should be free for private addresses.

    3 votes
    Vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
    You have left! (?) (thinking…)
  4. Meta/ Facebook

    We are subscribing to your service and had over 3.000 users so far. But none is showing the FACEBOOK data leak. How can this be?

    1 vote
    Vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
    You have left! (?) (thinking…)
  5. Add unsubscribe steps in FAQ

    There's a old thread from 2015 and the response mentions there's an unsubscribe link in emails. I do not see the unsubscribe blurb in the emails I have received since May 2023. If going through the "opt-out" process is the new method, the wording is confusing as there is no mention of being removed from breach notifications. "Opting-out provides various mechanisms to ensure your email address is no longer publicly searchable. After verifying control of the address, you'll be given 3 different options that put you in control of how your visibility should be removed from both existing data breaches…

    1 vote
    Vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
    You have left! (?) (thinking…)
    1 comment  ·  Admin →

    This is already in place:


    1. Notification emails sent to individuals have the following text: "If you don't want to receive any future breach notifications, just click here to unsubscribe"
    2. Notification emails sent to domain monitors have the following text: "You can see which of the accounts you're monitoring were compromised and manage your domains via the domain search dashboard. You can also unsubscribe domains from future notifications via the dashboard."


    Opting-out is a different mechanism unrelated to services you've consciously subscribed to and is explained as follows: "Opting-out provides various mechanisms to ensure your email address is no longer publicly searchable."

  6. K-12 domains

    is there EDU pricing for K-12 and do you have resellers that NY schools can use?

    1 vote
    Vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
    You have left! (?) (thinking…)
  7. New tier for home users

    I self-host VaultWarden which has an option for an api key. For a small home user, I would love a cheaper option that would be rate limited by X requests per month or year so I can make use of this feature for my family. I do not need the 10 rpm of the current lowest tier.

    1 vote
    Vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
    You have left! (?) (thinking…)
  8. add a way to pull up all the accounts made from an email

    Add an option to list all the accounts made and available from an email.

    1 vote
    Vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
    You have left! (?) (thinking…)
  9. Higher Ed Discount

    As we are not awash in money it would be appreciated if there was a Higher Ed discount of some sort. As students come and go they still stay on the list as pwned users even if they are no longer enrolled. Like you, we are a proponent of research and public service.

    2 votes
    Vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
    You have left! (?) (thinking…)
  10. Allow challenging of unrealistic results...

    I have a small private domain used just for my family, which has 5 mailboxes and at most a dozen email adresses including role accounts like security@ or postmaster@ - yet HIBP tells me I need to sign up for Layer 3 subscription as I apparently have 128 breached accounts.

    Clearly there is something wrong, but there's no way for me to even see what's wrong because I don't have a subscription. There must be some error in the HIBP database, but there's no way for me to check or even to ask someone to check it...

    1 vote
    Vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
    You have left! (?) (thinking…)
  11. Consider offering a free tier for nonprofits

    It looks like some services have been put behind a paywall. Which in truth I can understand. We offer services to small budget local governments in Texas - this information is helpful to secure public workers and their county emails.

    1 vote
    Vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
    You have left! (?) (thinking…)
  12. Create a Mastodon account

    Given the exodus of accounts from Twitter to Mastodon, as well as its close relationship to the open-source and information security communities, I think you should create a Mastodon account and have it basically, at the very least, reflect what your Twitter account is saying - which is relatively easy to do via tools such as this: https://moa.party/

    3 votes
    Vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
    You have left! (?) (thinking…)
    1 comment  ·  Admin →

    Done! I'd previously tried to reach out to @haveibeenpwned@mstdn.social and ask them to hand over the account but got no response. I've just set up @haveibeenpwned@infosec.exchange instead and verified it as the owner of the domain. I'm not sure how I'll actually use it yet (only a very tiny portion of the audience is there), but at least it now has a presence.

  13. QuestionPro information

    Thank you for your service.

    I received a notice from you that I had been pawned. After receiving your confirmation that I -WAS- hacked, I then did a web search on the QuestionPro hacking. It appears they are declining to confirm the incident. I can prove that it occurred.

    I assign a different email to EVERY person I exchange emails with, especially vendors. The email address you indicated was hacked was assigned to ONLY ONE MAJOR US POWER SUPPLIER. It is 100% clear to me that my supplier gave my email address to QuestionPro which was subsequently hacked.

    1 vote
    Vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
    You have left! (?) (thinking…)
  14. update the breached password list download again

    I noticed you stopped updating the download for breached passwords. I would like to continue to have an up to date data set to prevent users form choosing breached passwords but I will not use the API.

    I don't want the availability of something like registering for an account to be tied to an external service, nor do I want to slow the process down by waiting on an external API.I just want an up to date list to check locally and decide to accept or reject the password my user is trying to choose.

    3 votes
    Vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
    You have left! (?) (thinking…)
  15. Display the Bitcoin Cash donation address as CashAddress

    On the donation page the Bitcoin Cash donation address is displayed in the old legacy format (1DQZe241VSm5VjY1YeAyiWQR5VFH3heCtJ).
    Most wallets (probably 100% of all user facing once) supports the CashAddress format (bitcoincash:qzypv5j3ce6g57x9te25lgx0z6af8ehz2c8tudzpaf in this case) and using the legacy format for bitcoin cash is discouraged due to a risk of sending to an invalid address.

    2 votes
    Vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
    You have left! (?) (thinking…)
    1 comment  ·  Admin →
  16. I reiceived an email that I'm in the Epik hack, but I have never had an account there so it seems something is off.

    I reiceived an email that I'm in the Epik hack, but I have never had an account there so it seems something is off with hibp?

    1 vote
    Vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
    You have left! (?) (thinking…)
  17. Erroneous link to v2 API documentation

    On page https://haveibeenpwned.com/PwnedWebsites the link on the sentence "These are accessible programmatically via the HIBP API" still redirects to the deprecated v2.

    1 vote
    Vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
    You have left! (?) (thinking…)
  18. API access: Recurring yearly payment

    This would help us alot as a company. Doing monthly bill mapping with a corporate creditcard is not working for us :-)

    This is coming soon! Announcement and details here: https://www.troyhunt.com/expanding-and-enhancing-the-have-i-been-pwned-api/

    385 votes
    Vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
    You have left! (?) (thinking…)
  19. Create different pricing for different rate limits

    Right now there is a 1.5-second delay time b/w request, which is a long delay wait-time for us.
    Currently, we have to thread multiple API keys together to decrease the rate limit, though we'd rather only have to use one and pay a bit extra.
    It would be very helpful if we could pay extra to have a lower rate limit (e.g. think tiers for rate limits maybe?)

    This is coming soon! Announcement and details here: https://www.troyhunt.com/expanding-and-enhancing-the-have-i-been-pwned-api/

    119 votes
    Vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
    You have left! (?) (thinking…)
  20. Offer a direct link to an account's breaches

    It would be helpful if we could directly link to an account's breaches info.

    For example, using an URL like https://haveibeenpwned.com/#example%40example.com to directly open the pwned information for example@example.com.

    This would make it easier to integrate HIBP into other products without having to recreate the whole pwned information webpage.

    1 vote
    Vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
    You have left! (?) (thinking…)
← Previous 1 3
  • Don't see your idea?

General

Categories

Feedback and Knowledge Base