Skip to content

Comment on Ask HN: How to monitor Darkweb if credentials of our SaaS product are leaked?

Comments

It’s called the “Dark Web” for a reason. Monitoring tools may exist but they do not and can not cover every avenue, or even a small fraction of them.

There may be scanners etc but I think your best bet is to ask the security provider for recommendations. They identified the issue and notified you - it sounds like they’re a third party worth keeping around.

In the mean time, assume that creds can be stolen and there’s nothing you can do about it: what do you do about that? You have many options: rate limiting, IP checks, detecting unusual activity. I’d start there.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.