The Naz.API dataset is a massive collection of 1 billion credentials compiled using credential stuffing lists and data stolen by information-stealing malware.

Credential stuffing lists are collections of login name and password pairs stolen from previous data breaches that are used to breach accounts on other sites.

Information-stealing malware attempts to steal a wide variety of data from an infected computer, including credentials saved in browsers, VPN clients, and FTP clients. This type of malware also attempts to steal SSH keys, credit cards, cookies, browsing history, and cryptocurrency wallets.

  • trevor@lemmy.blahaj.zone
    link
    fedilink
    English
    arrow-up
    2
    ·
    6 months ago

    I agree with doing this, but the main drawback is that you can’t easily check all of your unique aliases in HaveIBeenPwned without scripting something and paying for API access.

    I have hundreds of unique aliases for my accounts, but no simple way to see when/if the services that use them are breached.