Like many people, I am concerned about security and privacy online but, until now, I have been too lazy in regularly changing and varying passwords or in using tools such as two-step or two-factor verification. Then I came across this article which contained this paragraph:
How might a digital EPA function? Well, it could do some of the work that individuals do today. For example, the website of Australian security expert Troy Hunt, haveibeenpwned.com (“pwned” is how elite, or “l33t,” hackers, or “hax0rs,” spell “owned”), keeps track of nearly 5 billion hacked accounts. You give it your email, and it tells you if you’ve been found in a data breach. A federal agency could and should do that work, not just one very smart Australian—and it could do even better, because it would have a framework for legally exploring, copying, and dealing with illegally obtained information.
The haveibeenpwned website allows you to check if your email has been subjected to a data breach. As far as I can assess, the website is legit (it passed by antivirus and nothing suspicious came on a Mr Google search about the website or Troy Hunt) though I cannot verify that as a fact.
Below are the number of data breach incidents from hacking by year the incidents were made public, as publicly disclosed and monitored by Privacy Rights Clearinghouse. 2016 includes high profile incidents like Yahoo and LinkedIn. Obviously, there is likely to be many many more incidents which haven’t been found out or publicly disclosed.
Oh, and by the way, it looks like two-step or two-factor verification is deeply flawed also, as per this article. Nonetheless, I am told it’s better to have it than not.