Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

At one point I responded to a haveibeenpwned notice by immediately having the user reset a password.

I've got over 200 users in a domain search (edit: for this particular incident), and nearly all of them were in previous credential breaches that were probably stuffed into this one. I'm not going to put them through a forced annoyance given how likely it is the breached password is not their current one, and I'm urging people to start moving in this direction unless you obtain a more concrete piece of advice.





Same here: reset on first beach (ROFB), but on subsequent ones only if it is no collection, eg a new infostealer breach.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: