this post was submitted on 25 Apr 2024
191 points (98.0% liked)

AssholeDesign

7575 readers
2 users here now

This is a community for designs specifically crafted to make the experience worse for the user. This can be due to greed, apathy, laziness or just downright scumbaggery.

founded 1 year ago
MODERATORS
 
you are viewing a single comment's thread
view the rest of the comments
[–] [email protected] 17 points 6 months ago (7 children)

My email address is literally registered on dozens of websites. I use a different completely random password, generated by a password manager, on every one of those sites. How would I know which website and which password was compromised based on this message?

[–] [email protected] 2 points 6 months ago (6 children)

Here's a neat trick that works with some providers: you can include a + sign and an extra string of characters and it will still be delivered to the same address. Example:

[email protected] will receive the mail for [email protected]. So you can register with a different email address everywhere yet it all goes to the same account. If your account gets leaked or breached you'll know where it happened thanks to the extra information behind the +.

[–] [email protected] 1 points 6 months ago* (last edited 6 months ago) (2 children)

But they hide everything before the @ so how does that help?

[–] [email protected] 1 points 6 months ago (1 children)

You can narrow it down by length. Not perfect but it's a start. Unless the *****s are always the same length like in some password fields. Hard to tell from the message.

[–] [email protected] 1 points 6 months ago* (last edited 6 months ago)

It's not a good method is it? It relies on others not being really stupid

Oh hay Lets just make they reacted paid rise same length render tone, since that is real really easy.

load more comments (3 replies)
load more comments (3 replies)