Hacker News new | ask | show | jobs
by Hikikomori 408 days ago
If you read the full article you'll see its not just from database dumps.
1 comments

Have I Been Pwned listed me in the ALIEN TXTBASE Stealer Logs. I went through the Notify me tab, got a verification link to check for my personal records, and all I got was this lousy:

"No domains were found for your email address. Whilst your email address was found in a stealer log, no websites were found alongside it. This can be due to the way the log was formatted."

TL;DR: You could try my email in there, believe credentials were stolen, when that might be recycled leak stuffing.

Alternative explanation - someone emailing you is infected by a stealer on their machine - they typed your email into the "to field" and that was captured by a key logger on their system.
Absolutely. Now, how do I sort things out? And eventually clear my name so people searching for my email don’t jump to conclusions regarding my OPSEC…
"By searching for his personal Gmail address (which I'm not sharing) in Have I Been Pwned, he appears in 51 data breaches and in 5 pastes. These include a 2013 breach of 153 million Adobe users, a 2016 breach of 164 million LinkedIn users, a 2020 breach of 167 million users from Gravatar, a 2024 breach of the conservative news site The Post Millennial, and many more."

Stop reading Ars and your name will be cleared. This isnt real journalism, it is Ars-washed political talking points.

I’d be in 3 of those breaches. One of the rules working in government was never use your personal email or ID for anything.

If you had to work in the nightmare of secure systems, the computers are literally in a different room, there is no Internet access in there, and you can’t take your smartphone in there.

You fly jets long enough, something like this happens.