logoalt Hacker News

bjourneyesterday at 9:52 AM8 repliesview on HN

Heard of haveibeenpwned? You'll end up there, eventually.


Replies

vikaveriyesterday at 10:01 AM

If you end up, for some reason, being one of those unlucky individuals whose Google account gets banned and all your other accounts are behind Google login, then you truly have been owned.

zelphirkaltyesterday at 10:21 AM

You mean when using "sign in with" and then using a shitty password for your social media account?

If you use e-mail and password with a good password manager, that runs locally on your device and generate good random passwords, it is unlikely you will end up on haveibeenpwned, and even if one website does shit, the blast radius is only one account on one website.

show 1 reply
bravetraveleryesterday at 10:11 AM

Risk Bob's Salad Shack leaking an inconsequential, unique, credential or bind everything to the whims and identity of a single organization; hmm.

Nextgridyesterday at 10:08 AM

Ending up on HaveIBeenPwned is only a problem if you reuse passwords.

show 1 reply
raincoleyesterday at 10:24 AM

Password manager.

Before inevitable "what if your password manager is hacked...," what if your google account is hacked / banned?

show 2 replies
danelskiyesterday at 10:14 AM

Sign-on with the external identity provider doesn't help if data related to your account like the billing information, your government ID info etc. are released in the breach, that's the sore point.

palatayesterday at 2:44 PM

- Complains about age verification because it is "not private"

- Uses Google SSO to sign in everywhere

wraptileyesterday at 10:17 AM

People will know that my password was y!2TvM8h3dpvw4 for one particular website at some point. What do I lose here? Google/Apple incurs much greater risk that is entirely out of your control.