I love following ZDNet ; great information on current and new technologies as well as practical guidelines on Information technology (IT), privacy and security. There latest article was in relation to a tool allowing you to find out if your email address was stolen in a hacker breach. The online tool is called HackNotifier .

This tool was created by Julian Pulgarin a candidate for Bachelor of Software Engineering at the University of Waterloo in Ontario, Canada.

According to ZDNet:

Julian decided, what with all the lists of personal information being released to the public by the likes of Anonymous, Wikileaks, AntiSec, and LulzSec, individuals might be worried that their information might now be out “in the wild.”

So Julian’s been curating the released data. He’s built a database containing all the email addresses (over 1.4 million addresses, including the Booz Allen Hamiliton breach).

All you have to do is go over to HackNotifier.com. Enter your email address (which he promises me he’s not capturing), and the site will tell you if your email address is in any publicly available leaked database.

Although there is a statement of purpose and use on the HackNotifer website stating that:

HackNotifer is completely safe to use. All emails that are checked are only used to make sure that your accounts are secure. Your email is never stored without your permission.

Several questions come to mind immediately. For instance, how do they know what email is linked to a specific account? How did they get access to the leaked information found in the database? Do they have permission to use such information in light of various class action lawsuits? Am I missing something?

I’m too much of a coward to try, but despite my misgivings, I thought this was a genius undertaking in relation to the numerous data breaches we have been witnessing lately.

Let me know what you think. And if anyone does have the guts to try, give me some feedback.

Marie-Yosie Saint-Cyr, LL.B., was called to the Quebec bar in 1988 and is still a member in good standing. She practised business, employment and labour law until 1999. For over 12 years, Yosie has been the Managing Editor of the Human Resources and Compliance Collection from First Reference. She is the managing editor of the Human Resources Professional Association (HRPA) of Ontario’s monthly member e-newsletter ELAW. Yosie is one of Canada’s best-known and most-respected HR authors, with an extensive background in employment and labour law across the country.
[click on the author's name for more information]

up

7 Comments on “ZDNet: How to Find Out if Your Personal Info Has Been Leaked in a Security Breach”

  1. Bruce says:

    I tried it using the 3 email accounts I have, and all came back clean; whew! The free search does end up with a pitch for a subscription (1 yr for 1 email address is $9.99). If the service is effective & provides timely notification, the fee seems eminently reasonable given the recent spate of high profile data thefts. Also, considering some of the less probable events we insure against, … .

  2. David Collier-Brown says:

    I'd prefer to see the hacked companies notifying the victims, as they have the clear relationships between the emails and the accounts, but until and unless we can guarantee reliable notifications, a fallback is a good idea.

    From the brief description on site, he's done a hash-table of the email addresses, thus completely anonymizing them, and reports to individual if the address they submit, when hashed, matches an entry in the table.

    A "hash table" is a classic way of encrypting information in a way that cannot be reversed. It is heavily used when one must anonymize personal or identifying information in a body of data one is studying. [Bruce Schneier. Applied Cryptography. John Wiley & Sons, 1996. ISBN 0-471-12845-7.]

    The advantage of hashing is that renders your email address anonymous: the disadvantage is that he probably can't tell you which account was compromised. Considering that they're in the hands of criminals, I suspect if any account of yours is compromised, they all will be in a week or so…

    –dave

  3. Mike says:

    I tried it – I got one hit for an email account I already knew was hacked (I was notified by the compromised website).

  4. Julian Pulgarin says:

    Thanks for mention Yosie! Here are my answers to your questions:

    1. There is no matching of "account" done. We have parsed various security leaks, and store all the emails that were in the leak inside our database. When you enter your email on our website we check your email against our database to see if it was contained in any of these leaks.

    2. The leaked information is taken from publicly available database dumps, such as the ones hosted on http://lulzsecurity.com/

    3. I am fairly certain that we are in the legal clear in regards to solely storing the emails (we do not store passwords or any other info contained in thease leaks).

    If you have any more questions don't hesitate to contact me at jpulgarin@hacknotifier.com

  5. Julian Pulgarin says:

    David, currently we do not store the emails as hashes. This is to allow future services where we protect entire domains (impossible to do through hashing).

  6. Thanks Bruce, David and Mike for trying it… after seeing your comments I did try it and my email seems to be ok for now. Julien much appreciation for answering my questions… great endeavour!

  7. David Collier-Brown says:

    Thanks for the correction, Julian!

    –dave

Make a comment:

Note that some comments may be moderated. If you have not had an approved comment here before, your comment will be held for approval. We are glad to publish comments that address issues raised in the post or other comments on it and that contribute to a fruitful discussion. We do not publish comments that seek to promote commercial products, that make personal attacks, or that seek personal legal advice.

Although we do not require it, we ask that in making a comment you use your full name. You must supply a valid email address, which will not appear with your comment.

 

SlawTips      

SlawTips Good Communications = Satisfied Clients
Thursday, February 23

As Richard Ferguson, a lawyer friend of ours says on his email message: “People may forget what you said…. People may forget what you did…. but people will never forget … »»

Practice

SlawTips Current Awareness
Wednesday, February 22

There are two possible approaches to personal current awareness: Develop excellent searching skills so that you can find what you need when you need it Pick a fairly narrow specialty … »»

Research

SlawTips Top 10 Financial Errors: #10 Rely on the Lottery for Your Partnership Retirement Plan
Thursday, February 16

“It is better to have a permanent income than to be fascinating” was said once by Oscar Wilde. The final tip in this series is the capstone issue in our … »»

Practice

noted on Slaw    

MLB Selected Case Summaries    

These summaries of selected recent cases are provided each week to Slaw by Maritime Law Book.
More information.

  • Limitation of Actions - Actions in contract - Actions for debt - General

    Moody died on December 3, 2005, leaving four adult children. Pursuant to Moody’s will two of her children, James and Tyrell, were appointed executors of the estate. It was alleged that, during her ...

  • Barristers and Solicitors - Discipline - Suspension - For professional misconduct

    McLean pled guilty five counts of conduct unbecoming a lawyer. The Discipline Committee suspended him from practice for four months and placed him on indefinite supervision. McLean appealed the length of the penalty.

    The Saskatchewan ...

  • Mines and Minerals - Operation of mines, quarries and wells - Licences and permits - Appeals or judicial review - Standing - Costs

    Grizzly Resources Ltd. (Grizzly). made an applications to the Energy Resources Conservation Board to drill two sour gas wells on the same site. ...

  • Narcotic Control - Offences - Trafficking - Elements of

    The accused was charged with trafficking in cocaine. The trial judge granted the accused’s motion to discharge the charge. The Crown appealed.

    The Saskatchewan Court of Appeal allowed the appeal and ordered a new trial.

    Link ...


TalkLaw/ParLoi    

This is a listing of a few upcoming events in Canada of interest to lawyers, law students, legal librarians, and others involved in the practice of law.

Clicking on any event in the list below will give you access to more information and to links allowing you to see the full entry and to add the event to your own calendar.

Click this link for a fuller version of the TalkLaw/ParLoi calendar of events and for instructions as to how to add events and calendars to your own calendar.

Switch to our mobile site