5.1: Set Up Breach Alerts
Set Up Breach Alerts
In Lesson 1.2 you met Have I Been Pwned, the public record of breach dumps, run as a free service. In 2.5 you queried its password database from this site. Now you turn it from a lookup into a tripwire: HIBP will email you, automatically, whenever an address of yours appears in a newly loaded breach. This is the whole “monitoring” layer the course promised, and it takes about fifteen minutes for every address you own.
Why alerts beat checking
You could visit the site and search your email every few months. You won’t, though. Nobody sustains a habit whose payoff is usually “nothing new.” Subscribing inverts the deal: silence means clear, and the one email you ever get is the one that matters. Monitoring you have to remember isn’t monitoring; it’s a chore with your name on it. The design goal for this whole module is systems that work at three in the morning without you.
Do it now: subscribe every address from your 1.4 list
Go to haveibeenpwned.com → Notify me. Enter your primary email, confirm the verification message it sends, and that address is watched for good. Then repeat for the others on your Lesson 1.4 map: the old address that still receives resets for accounts you made in 2012, the shared family address, the work-adjacent personal one. Leaks don’t care which of your addresses is fashionable, and the forgotten one is on more old sites, not fewer.
While you’re there, run one search on each address against the existing record. Expect hits. Most addresses more than a few years old show up in several breaches, and after Module 2 that history is already defused — the old passwords are retired, and unique ones guard everything now. The reason to look anyway is calibration. Once you’ve seen your own address in the historical record, the next alert reads as a familiar genre instead of a fright.
The watchers you already own
Two more tripwires are already in your pocket. They just need noticing, not installing.
Your password manager’s report. Watchtower (1Password), vault reports (Bitwarden), and their equivalents don’t just flag reused passwords. They continuously compare your stored passwords against the same breach corpus HIBP maintains, and flag any that turn up. When a site you use gets breached, the vault entry sprouts a warning badge, often before the company’s own disclosure email arrives. You’ve been building this database all course; now it starts working shifts for you.
Your platform’s checkup. Google’s Password Checkup and Apple’s compromised-password warnings do the same for anything stored in those ecosystems, and they surface it in Settings with a red number you shouldn’t ignore.
That’s three overlapping watchers — HIBP on your addresses, the manager on your passwords, the platform underneath — with different blind spots and one shared property: none of them requires you to remember anything.
What an alert really means
One expectation to set before the first one lands: a breach alert is routine, not an emergency. It means one site lost one database that happens to include one address of yours, and thanks to Module 2, the password there opens nothing else. The response is a calm, bounded procedure that takes about twenty minutes, and Lesson 5.3 drills exactly that. First, though, 5.2 covers the trick that makes alerts surgical: knowing which site leaked before the alert even tells you.