eupolicy.social is one of the many independent Mastodon servers you can use to participate in the fediverse.
This Mastodon server is a friendly and respectful discussion space for people working in areas related to EU policy. When you request to create an account, please tell us something about you.

Server stats:

223
active users

#haveibeenpwned

1 post1 participant0 posts today

Have I Been Pwned unveils Major Redesign with Confetti Celebration & Unified Dashboard.

The updated interface still highlights a prominent search box for users to check if their email addresses have appeared in a data breach, but after entering an email address, the response experience now shifts: when no breaches are found, users are greeted by a celebratory confetti animation.

haveibeenpwned.com/

Replied in thread

@EllyvA : precies. Ook ik ben mens en dus maak ook fouten en doe onverstandige/risicovolle dingen; ik ben als de dood dat ik een keer ergens intrap.

Ik hoop dat ik dan net zo dapper ben als Charlotte Cowles (thecut.com/article/amazon-scam - m.i. zeer lezenswaardig) en Troy Hunt (*) in troyhunt.com/a-sneaky-phish-ju.

In security.nl/posting/840236/Vei leg ik uit hoe je het veiligste kunt inloggen (dit helpt niet tegen foute sites waarop je nog geen account hebt).

Aanvulling verderop in die pagina (directe link: security.nl/posting/876137): zet altijd "Waarschuwen voor onveilige verbindingen" aan als jouw browser dat ondersteunt (met screenshots voor Safari op iPhone/iPad: infosec.exchange/@ErikvanStrat).

(*) Troy Hunt is beheerder van haveibeenpwned.com/About

The Cut · How I Fell for an Amazon Scam Call and Handed Over $50,000By Charlotte Cowles

#TroyHunt fell for a #phishing attack on his mailinglist members: troyhunt.com/a-sneaky-phish-ju

Some of the ingredients: #Outlook and its habit of hiding important information from the user and missing #2FA which is phishing-resistant.

Use #FIDO2 with hardware tokens if possible (#Passkeys without FIDO2 HW tokens are NOT phishing-resistant due to the possibility of being able to trick users with credential transfers: arxiv.org/abs/2501.07380) and avoid Outlook (or #Microsoft) whenever possible.

Further learning: it could happen to the best of us! Don't be ashamed, try to minimize risks and be open about your mistakes.

Note: any 2FA is better than no 2FA at all.

Troy Hunt · A Sneaky Phish Just Grabbed my Mailchimp Mailing ListYou know when you're really jet lagged and really tired and the cogs in your head are just moving that little bit too slow? That's me right now, and the penny has just dropped that a Mailchimp phish has grabbed my credentials, logged into my account and exported the mailing

“Infosec veteran Troy Hunt of #HaveIBeenPwned fame is notifying thousands of people after phishers scooped up his #Mailchimp mailing list.

He said the list comprises around 16,000 records and every active #subscriber will be receiving a notification and apology #email soon. …

Around half of these records (7,535), however, pertain to individuals who had #unsubscribed from the list”

#InfoSec / <theregister.com/2025/03/25/tro>

The Register · Infosec pro Troy Hunt HasBeenPwned in Mailchimp phishBy Connor Jones

I'm "one of 28,445,106 people pwned in the French Citizens data breach".

I've been to the Paris airport once, but I'd hardly call myself French.

Breach info (per haveibeenpwned.com/):

Breach: French Citizens

Date of breach: 25 Sep 2024

Number of accounts: 28,445,106

Compromised data: Device information, Email addresses, IP addresses, Names, Partial credit card data, Phone numbers, Physical addresses

Description: In September 2024, over 90M rows of data on French Citizens was found left exposed in a publicly facing database. Compiled from various data breaches, the corpus contained 28M unique email addresses with the various source breaches each exposing different fields including name, physical and IP address, phone number and partial credit card data including payment type and last 4 digits.

haveibeenpwned.comHave I Been Pwned: Page not foundHave I Been Pwned allows you to search across multiple data breaches to see if your email address or phone number has been compromised.