• Please take a moment to look over the Suggestions & Feedback rules before making a post: READ RULES HERE

Firefox says BHW is doing Data Breach.

Status
Not open for further replies.
True.. I have seen the sql dump. Saw my username, email ,ip , hashed password. It was back in 2014.

Every major company is breached one day..even apple's user data is breached in 2010.
Why we are discussing in 2018 lol..

It happened . accept and change your passwords..

Security is myth. Lol

also that dump is useless. while it maybe useful for brute forcing the hash, the email lists are simply useless.
you can't just dump viagra landing page there, since all of you guys are the one who promotes it :D
 
Like I said before I was a huge fan of Firefox from 2005-2010 but after that, it became slow as turtle lol.

Why do you think it went this slow and sluggish?

2010 was right around the time they split into channels and didn't keep a holistic view on their release program went all trendy loft space instead - it's still great as long as you run it raw without plug-ins
 
also that dump is useless. while it maybe useful for brute forcing the hash, the email lists are simply useless.
you can't just dump viagra landing page there, since all of you guys are the one who promotes it :D
how about promoting an SEO service? SEO Tool? Facebook custom audience? :p:p ideas are bulletproof my friend
 
Back from 2005-2010, Firefox WAS my fav because it was very smooth and fast.

But over the years it has become too sluggish. :(

Anyone know why?
firefox is not slow, CHROME is fucking fast.

Firefox changed their engine, you should checkout firefox quantum now, atleast once. They are very resource friendly now and upgrading their code regularly as well.:anyway::anyway::anyway:

True.. I have seen the sql dump. Saw my username, email ,ip , hashed password. It was back in 2014.

Every major company is breached one day..even apple's user data is breached in 2010.
Why we are discussing in 2018 lol..

It happened . accept and change your passwords..

Security is myth. Lol
That's RIGHT, PRIVACY IS A MYTH.:D

BTW i am using firefox and not seen any warning like that.
Change some setting in firefox and you're good to go. :p
 
there is no proof of a data breach in the first place.
You don’t think the publicly accessible database dump is proof of a breach?

Did you just give out user’s private emails in 2014?
so how can this be considered a personal data breach?

"personal data" means data relating to a living individual who is or can be identified either from the data or from the data in conjunction with other information that is in, or is likely to come into, the possession of the data controller;

https://www.dataprotection.ie/docs/What-is-Personal-Data/210.htm

Emails & IPs are personal data.

Emails & IPs are included in the database dump scraped list of 700000 members.

Not a difficult concept to grasp.
 
You don’t think the publicly accessible database dump is proof of a breach?

Did you just give out user’s private emails in 2014?




https://www.dataprotection.ie/docs/What-is-Personal-Data/210.htm

Emails & IPs are personal data.

Emails & IPs are included in the database dump scraped list of 700000 members.

Not a difficult concept to grasp.


@elavmunretea you keep calling it publicly accessible and yet missing the point - throw me the link - via pm if you prefer, really easy to verify it was my early days on BHW so I was using my ultra paranoid email.

Proof - it's the simplest of all concepts to grasp .
 
it was my early days on BHW so I was using my ultra paranoid email.

Please don’t tell me that I’m the only fuknut that gave his real name and address when I signed up for Jr.?

Djeesss, I do have a lot to learn...
 
This has to be related to the old breach. Guys just change the password and forget it lol. It will be great to have 2FA login nevertheless (or do we already have it?).
 
I'm not even getting into this as @nuf-ced has covered it but @elavmunretea - has nobody taught you that you can talk to people without being aggressive, rude or sarcastic?

Did you just give out user’s private emails in 2014?

Not a difficult concept to grasp.

You know there's a polite way to ask questions, yes? When everything you post in this section is a complaint about a new thing and when they're all written in a challenging, snarky manner then you're not dropping truth bombs, you're not "telling it as it is" - you're just turning into white noise. Because when you make every single tiny thing an issue, then the important things get drowned out.

In future, carry these debates out civilly without implying people are stupid or making loaded comments if you want to be taken seriously.
 
That's great. I will enable mine then.

@nuf-ced

Looks like these guys had the dump
Code:
https://raidforums.com/Thread-BlackHatWorld-Database-Leaked-Download

Cheers @Gogol - but this is one of those create a load of hoops to jump through and we'll give you a nice shiny gold plated list of nothing traps.

Look I'm not saying it never happens (note hasn't on BHW as far as I'm aware) - but the point of this thread is that HIBP and the Troy Hunt project base data that they are selling publicly which is based on his opinion of what's hacked data and as he states in his FAQ's a lot of his data is taken on the word of hackers. Who he doesn't know but he will use to build his public profile and of course hackers never mess with people......... Ever. :suspicious:
 
Last edited:
.......
Change some setting in firefox and you're good to go. :p

It's part of their latest set of internet health future releases more cleanly explained in a press release here the problem is the data that they based this partnership on is massively flawed for the reasons I mention above somes going to get dropped in the sh*t and I'm thinking Mr. Hunt or whoever he sells HIBP to will be on the receiving end of any number of legal challenges.
 
Here you go: https://databases.today/search.php there are quite a few other in there but I'm sure you can find the relevant file. I have checked it and the file is clean:

https://www.virustotal.com/#/file/4...e64c1cf2c135a76384861551b63c5d3f1bc/detection

Now I'm not saying anyone's information is in there or not or even picking a side to this argument, I don't really care but people are free to check this if they want.

I've checked this before, don't know if from same website. But definitely a database dump of personal information.
 
Here you go: https://databases.today/search.php there are quite a few other in there but I'm sure you can find the relevant file. I have checked it and the file is clean:

https://www.virustotal.com/#/file/4...e64c1cf2c135a76384861551b63c5d3f1bc/detection

Now I'm not saying anyone's information is in there or not or even picking a side to this argument, I don't really care but people are free to check this if they want.

Thanks @disposableher0 but I refer you to my point above https://www.blackhatworld.com/seo/firefox-says-bhw-is-doing-data-breach.1041561/page-2#post-11195295 - if it's not verified data then just because it's called BlackHatWorld doesn't mean it is BlackHatWorld data, and as per my tin hat post this doesn't contain my data. If I upload a file called "Nixon Tapes" or "Who Shot JFK" doesn't mean it contains nessies postcode.
 
We're all entitled to our opinion but I feel I've made my point here - if the data isn't independently verified then (and that doesn't mean Harry says that's me!) .... then it's about as useful as a chocolate teapot.
 
Here you go: https://databases.today/search.php there are quite a few other in there but I'm sure you can find the relevant file. I have checked it and the file is clean:

https://www.virustotal.com/#/file/4...e64c1cf2c135a76384861551b63c5d3f1bc/detection

Now I'm not saying anyone's information is in there or not or even picking a side to this argument, I don't really care but people are free to check this if they want.
I just checked this dump and my old username/email/skype etc are in there. :S
It has to be legit.
 
I do appreciate what your saying and as I said I didn't post it to stir the pot because I don't care. I can see data in there regarding myself and a very old account that I had but lost the ability to recover after losing the email account (may get in trouble for that one now).

Can I verify that data came from here well I suppose I can't and as someone said earlier security is a myth. When it comes to the internet you may as well assume any information you put anywhere on line is at risk and act accordingly.
 
Thanks all for your comments and support over the 2014 alleged breach - this rolls around every 6-12 months what @nuf-ced has stated above is supported by me and the BHW team. We've written about this many times, hardened our security and offered 2fa to all - as part of the standard way of things not in reaction to anything in particular - just being a responsible site owner.

Whilst reaching out to HIBP has proven fruitless, we've asked for explanations and or proof without real response (non-form letter response) as they don't have to.

We will consider legal action to receive this data and notify those using the HIBP data that much of the early content is fictitious/unproven. There is little more we can do at this stage. (edit) Well, there is but I ain't posting about it ;)
 
Status
Not open for further replies.
Back
Top