HN user

mgpalmer

2 karma
Posts2
Comments3
View on HN

Great work by the HIBP team as usual but I am puzzled by something, maybe someone can shed light on it?

I'm managing a domain search dashboard for a company, and for one domain all the recent stealer log breaches contained addresses with the domain - but all the local/user parts were bogus - for example, fabuchoy@example.org where fabuchoy was never a user, the email never existed.

So nothing is in danger but where do these bogus addresses come from? Is someone just trying to log in somewhere with random addresses (with our domain) and then the (failed) login attempt gets sniffed by some malware and ends up in the breach dumps? Or are the cybercriminals just padding their dumps with made-up addresses?

You're right. And Paypal's business support hotline, which I am now intimately familiar with, is already very bad and their backend merchant portal is a bad joke - I found dozens of bugs, untranslated strings, weird workflows...amazing what you can get away with when you're a monopoly :(

I am loathe to be a customer of Paypal and all its shady subcompanies - but they're the most-known online payment provider so we don't have a choice, and Braintree's APIs are more capable then Paypal's own.