Skip to content

Comment on Project Svalbard, Have I Been Pwned and its ongoing independence

Comments

It's interesting what HIBP reveals about both attackers and defenders.

HIBP held a long randomly generated password I used exclusively on tvtropes. It was in plaintext in a pw dump, suggesting they weren't even hashing at the time.

I contacted tvtropes a few times but got ignored with no announcement.

It's not a banking site, not sure what we should expect. But given compelling evidence of a breach and making no announcement to users seems irresponsible.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.