We are discontinuing the dark web report
81 points
9 hours ago
| 14 comments
| support.google.com
| HN
mholt
49 seconds ago
[-]
Discover (Card/Bank) also announced recently that they are stopping their dark web report service. I wonder if they just used Google, or if it's a coincidence...
reply
prepend
5 hours ago
[-]
I found the info not actionable because it wouldn’t say what actual values were posted.

I have a common name Gmail account. The password is rather complex and I would be surprised if it leaks as only I and Google know it. However, I would get reports that it’s on the dark web with blanked out password values. So I never knew if they actually compromised or just something else.

They would also report when some random site that used my Gmail address as user id was on the darknet that I don’t care about. I don’t care if my fidofido account is leaked. I never use it and if I did, then I would reset.

I think if the data were useful Google would have kept this up.

I bet they keep tracking though, just keep the reports internal.

reply
thesuitonym
2 hours ago
[-]
I never got the Google dark web reports, but my credit card used to send me reports constantly saying that my email address was 'found on the darkweb.' Okay, that's not useful information. If it showed me if there were associated passwords, that might be helpful, but just saying my address was found on the darkweb is meaningless. My email address is public information.

The worst part is, it was an email address I hadn't used in about 10 years, and they wouldn't let me take it out of the report.

reply
deepsun
16 minutes ago
[-]
Well you could change the email address you use for the financial services only, and keep it secret. Then it would be harder to impersonate you.
reply
levocardia
1 hour ago
[-]
I might be misremembering this but FWICR on Chrome it would link your saved passwords with the dark web report, and automatically recommend you change any account that had the same password as the "pwned" account found in the dark net. Was pretty useful.
reply
MinimalAction
2 hours ago
[-]
While this was a free service and thus Google is under no obligation to continue offering this service, this is still quite sad. They could have atleast bundled it for some tier of Google One paid subscription.
reply
therein
2 hours ago
[-]
It was as inactionable and useless as the ones that ID.me or whatever sends. Also calling it Dark Web report always felt super insincere. It had nothing to do with the "dark web", that just served a way to make it sound cooler and more hackery. Aren't we talking about something that's equivalent to HaveIBeenPwned?
reply
rolph
1 hour ago
[-]
dark web reports in general, seem to be a funnel for paid "security" and monitoring services, VPNs AV suites, typically you review your passwords for strength and redundancy, then you are redirected to buy some service, that ultimately looks like a data hoover, and put everything in a cloud scheme. now we have AI and FOMO to hook and reel in, seemingly more effective than darkweb boogeymen for adoption and revenue.
reply
atomic128
3 hours ago
[-]
HTTP response dumps from the Tor dark web: https://rnsaffn.com/zg4/
reply
xxmarkuski
4 hours ago
[-]
I set it up for an old Google account that has been breached. It did a relatively good job, but HIBP has more data in my experience, albeit it mainly looks at emails, whereas Google's report can do lookups by full name, address, and phone number. I think it was useful, but did not get enough love to be like a second HIBP.
reply
bflesch
2 hours ago
[-]
Can one of the good souls at google please donate the data to archive.org?
reply
arccy
4 hours ago
[-]
did anyone ever get a report? i never got anything at all...
reply
breppp
3 hours ago
[-]
yes, it was a cool feature showing which of your data has leaked and in what leak

I remember email and phone being the major ones. A kind of improved haveibeenpwned

reply
lavezzi
3 hours ago
[-]
yes, but recent alerts don't seem to be reporting properly, which now makes sense given the news.
reply
tonytamps
3 hours ago
[-]
always with 2 days of a HIBP email
reply
eimrine
9 hours ago
[-]
Why was it opened? Is it that dark web where asassination markets and similar stuff happens?
reply
stuaxo
7 hours ago
[-]
That market was fake, the report on it is really interesting (but the people submitting to it were real).
reply
martythemaniak
2 hours ago
[-]
Is there a product that will do go through the vast expanse of accounts you have and either delete them or mass-change their passwords? I basically I wish to shrink my online presence as much as possible, but doing it manually would mean finding all the various accounts I have, logging in, trying to close, etc. Seems like good fit for an LLM browser agent.
reply
rolph
1 hour ago
[-]
whenever you conceive of a weapon/tool to use in a time of struggle, make preparation for the possibility it may be siezed and directed against you.

such a product must be crafted to mitigate its own abuse, as well as the original problem.

reply
pluto_modadic
8 hours ago
[-]
huh. did their source / login get burned?
reply
9dev
9 hours ago
[-]
Another one for the graveyard!
reply
moebrowne
9 hours ago
[-]
reply
sunaookami
8 hours ago
[-]
Is this site still updated? Last entries are from 2024, no way Google didn't kill something this year.
reply
extraduder_ire
25 minutes ago
[-]
Looks like it's been updated since you posted this.

I know it's still active because I see someone with that handle posting on bluesky regularly.

reply
mungoman2
3 hours ago
[-]
I hear the team running the site was laid off.
reply
alex1138
3 hours ago
[-]
The people responsible for sacking the people who have been sacked have since been sacked
reply
7bit
8 hours ago
[-]
> While the report offered general information, feedback showed that it didn't provide helpful next steps.

Translation: We don’t actually want to keep spending time, money, and resources on this.

reply
nospice
2 hours ago
[-]
That's not how it reads to me. I think it's more that they feel they can't share enough information to make it useful without compromising their operating methods. Which is an eternal struggle with stuff like that: the bad guys are reading too.
reply
jajuuka
8 hours ago
[-]
That's my read. That it's not a revenue generator and taking server resources that could go to something that is making them money. They've at least added more things to Google One over the past year which softens the blow.
reply
ikiris
1 hour ago
[-]
Doubtful. The issue is probably the service needs to be moved to some framework that isn't deprecated and being turned off, and no one can justify side projects these days that don't sell an AI product.
reply