Hacker News new | ask | show | jobs
by vachina 1253 days ago
I wonder how many pwned email and password pair still match. Crooks can take control of these pwned accounts and pretend to be trustworthy.
1 comments

It depends on the risk. I have an account that was pwnd (with the same password) but there is no risk to me as there isn't anything useful in that account (not even a DoB, Address or even a Name.) Worse case, someone changes the password and locks me out. Then I'll create another account as it's not a big deal.
The point would not be that it's a threat to you (though it may be), it's that compromised accounts (like one you don't care about) are a threat to an ecosystem that can't identify whether a "user" is a human or a bot.

That is, your compromised account could be used in an attack and it would look like a human.