this post was submitted on 28 Sep 2023
49 points (100.0% liked)

Privacy

31876 readers
1 users here now

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

Related communities

Chat rooms

much thanks to @gary_host_laptop for the logo design :)

founded 5 years ago
MODERATORS
 

My password manager told me that my info was leaked, including IP address, address, email, personal information, and phone number, in a data breach of eye4fraud.com. However, I don't use eye4fraud, so it must have been a site that uses their services. I would like to change my login credentials on the site that shared my data with them (and stop using their service since they're sharing my info with a security company that was breached), but I don't know which site that was. I found this list of sites that use eye4fraud, but that list has over 1,600 entries. Other than reviewing every single sight on the list, is there a way of finding out which site that I use leaked my info?

top 19 comments
sorted by: hot top controversial new old
[–] Nurse_Robot@lemmy.world 23 points 2 years ago (4 children)

Probably not.

The best advice I've heard is to use a variation of your email (assuming you use Gmail) on every site you sign up for that indicates that website. This would allow you to immediately know.

So what is a Gmail Plus address? Say you have an email address like billgates@gmail.com. If you append a “plus” sign to your email username, Gmail will ignore anything written between the + and @ sign in the email address and still deliver the message to the same mailbox.

More info

[–] RQG@lemmy.world 4 points 2 years ago (5 children)

Does something similar exist aside from Gmail? Cus you know. Gmail.

[–] ebits21@lemmy.ca 8 points 2 years ago* (last edited 2 years ago)

You could use something like simplelogin.io to create aliases.

Integrates with password managers like Bitwarden nicely to generate aliases.

I think many other services support the + trick though too. The downside is that spammers know the + trick and can find out your base email easily; they can’t if you use an alias.

[–] Triton@lemm.ee 8 points 2 years ago (1 children)

I think it's a fairly standard feature. At least Protonmail also supports this kind of "alias".

[–] DudeDudenson@lemmings.world 1 points 2 years ago* (last edited 2 years ago)

If I'm not mistaken it's part of the original spec, Dylan beattle had a bit in a talk about email at some point

Edit: I was in fact mistaken it's a Google only thing and not part of the spec

[–] elltee@lemmy.one 5 points 2 years ago

Protonmail supports + addresses as well. Not sure about others.

[–] thesmokingman@programming.dev 4 points 2 years ago

YMMV on all of these. These are things I use or have considered.

[–] appel@whiskers.bim.boats 2 points 2 years ago (1 children)

Afaik this is not a feature unique to Gmail, it's a feature of the email system as a whole. Same with a dot. Any characters after a plus or dot in the first part of the email are ignored.

[–] Nurse_Robot@lemmy.world 4 points 2 years ago

I'm fairly certain you're wrong about the "." in an email address

[–] ohwhatfollyisman@lemmy.world 2 points 2 years ago

more than that, dots don't matter in gmail. bill.gates@gmail.com is the same as billgates@gmail.com, or as b.i.l.l.g.a.t.e.s@gmail.com. they all funnel into the id with which yiu had signed up.

this allows you to put various permutations of your email id for varioua online services.

[–] DudeDudenson@lemmings.world 2 points 2 years ago

This breaks a lot of sites that try to sanitize addresses (don't ask me why they do it)

Had it happen a couple of times that I would register and then it wouldn't recognize my email for the login or the confirmation email would never arrive. Never tried it again after that because it also ment I was unable to use that email for that site as well.

[–] vanontom@lemmy.world 1 points 2 years ago

I do this with passwords, too. For example, generate 15 digits and add 5 digits (like +LMY!) to end. Many of those sites will list which passwords were stolen, easy to see to see which sites have unforgivably poor security.

For email addresses, the variation is useful, but it's probably inevitable that it's eventually sold, stolen or guessed. Still nice to have the evidence.

[–] Synnr@sopuli.xyz 13 points 2 years ago (1 children)

Check your email addresses at haveibeenpwned.com and it will tell you what was all was leaked. eye4fraud was likely a fraud credentials hosting site that got hacked and leaked, and yours was in there, and it would have come from a previous leak.

[–] SHITPOSTING_ACCOUNT@feddit.de 6 points 2 years ago (1 children)

It's a "fraud prevention company" so some site you bought stuff from passed your data to them.

[–] Synnr@sopuli.xyz 5 points 2 years ago

Oh wow with a name like eye4fraud I never would have guessed they were legitimate and widely used but it looks like you're right.

[–] sqw@lemmy.sdf.org 2 points 2 years ago (2 children)

seems like it would be easier to work from your pw manager - did it not tell you which cred was compromised?

[–] DudeDudenson@lemmings.world 2 points 2 years ago

To me it sounds like his PW manager is just one of those that give fake warnings so you think they're doing something for you

[–] BackOnMyBS@lemmy.world 1 points 2 years ago

They only said it was eye4fraud. When I looked into that site since I've never knowingly used them, I found out that they manage security for other sites.

[–] backhdlp@lemmy.blahaj.zone 1 points 2 years ago

You can Ctrl-F and search for services that are in your PW manager.

If you can't find it, you can check https://haveibeenpwned.com/ for your email and password