Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I use unique email addresses per domain name, and I believe IHaveBeenPwned shows me at 39 unique email addresses breached! (So many that seeing which ones have been breached would now cost me $22 / month... IHaveBeenPwned is starting to feel like an extortion racket of its own..)


If you're using the same domain for each of your email address, HIBP has a domain-wide search feature which is free (but you need to register to validate your domain)


I've registered (years and years ago) and I get emails saying how many, but to see which emails they want lots of money.

(If I'm wrong their interface is very confusing and I cannot find the free access.)

Specifically it says this:

> Insufficient subscription. Only subscription-free breaches will be returned for this domain.

So I'm able to see 37 email addresses on my domain have been breaches, but I can't see which without paying $22 / month - https://haveibeenpwned.com/Subscription

> Domain search restricted: You don't have an active subscription so you're limited to searching domains with up to 10 breached addresses (excluding addresses in spam lists). Only results for subscription-free breaches are shown below, upgrade your subscription to run a complete domain search. If you believe you're seeing this message in error, make sure you're signing in to the dashboard with the correct email address (check your latest receipt if you're unsure).


Quoting Troy from a thread beneath the article:

> The easiest approach in that case is to take out the subscription, then immediately cancel it. It'll still last the full month, more here: https://support.haveibeenpwned.com/hc/en-au/articles/7707041...


I feel you. The aggregate email breach list just feels like a rainbow table at this point.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: