Skip to content
>_ITDITDWeb Security Platform
tag

accounts

2 articles with this tag

2026-10-06

How to check if your password was leaked: using Have I Been Pwned safely, and the checks already built into your browser and phone

A guide to checking for leaked passwords. Have I Been Pwned (HIBP) tells you whether an email address appears in a known data breach, which service it came from and what kinds of data leaked. Its password check (Pwned Passwords) hashes the password on your device and sends only the first five characters of the hash, so the password itself is never sent (HIBP API documentation). This site's take: check your current passwords where they are already saved (Google Password Manager, the iPhone Passwords app, Edge Password Monitor, or your password manager) instead of typing them into a website, and use HIBP for email addresses. A 'not found' result is not proof that nothing leaked.

2026-10-06

Setting up GitHub two-factor authentication (2FA): authenticator app, passkeys, recovery codes, and what to do if you lose your phone

A guide to setting up two-factor authentication (2FA) on GitHub and avoiding lockout. Since March 2023, GitHub has been requiring 2FA, group by group, for users who contribute code on GitHub.com; once selected, you get a 45-day enrollment period and a 7-day grace period, after which you cannot use GitHub.com until 2FA is on. GitHub Docs recommends a TOTP authenticator app as the primary method with a passkey or security key as backup (passkeys, security keys and GitHub Mobile can only be added after TOTP or SMS is set up). This site's take: the common 2FA failure on GitHub is not account takeover but locking yourself out, and GitHub Support cannot restore an account whose 2FA credentials and recovery methods are all lost. Save the 16 recovery codes in a password manager and register a second method on the same day. While you are there, move to expiring fine-grained tokens, prune authorized apps and SSH keys, and check push protection and Dependabot alerts.