Our first sponsor for Reloop! ❤️
This means a lot to us. Thank you for believing in what we're building and supporting our open-source journey.
It's amazing to see people value the time and effort that goes into building in public.
@venkatofl Why not sponsor @reloop_labs? You already know what we’re building, and we’re in the same space. We’re open source, by the way!
Let me know if you’d be interested in sponsoring us. Would love to work together!
Github - https://t.co/Diq7g0gzi6
website - https://t.co/pEEMwuZtkO
Every conversation you have ever had with a company is now up for sale.
Google bid $10 million for Spirit Airlines’ internal business records, including emails and chats, during its bankruptcy proceedings, with personal information to be removed before the sale.
Large companies sell your data through formal bankruptcy proceedings; smaller ones sell it to deep web data brokers.
Encrata sponsors open source
If you maintain an open source project and are looking for sponsorship, we would welcome an introduction.
Email us a link to your website or GitHub along with a short description of your work, who it helps, and the support you are seeking.
The language of cybercrime: dark web slang explained (part 1)
Fullz
A complete package of personal information like names, address, date of births, phone numbers, identification details like SSN, and financial data.
Logs
Data stolen from an infected device like passwords, cookies, browser history, autofill data, and crypto wallet info.
Combo
A list of username-and-password combinations, usually collected from breaches, phishing, malware, or reused credentials.
Checker
Software used to automatically test whether credentials, cards, accounts, or other compromised information still works.
RDP (Remote Desktop Protocol)
Access to a Windows machine, usually sold using compromised credentials.
Crypter
A tool designed to make malware harder for antivirus or security software to detect.
Drop
An address, account, or intermediary used to receive stolen money, goods, or fraudulent payments, sometimes without their knowledge.
Mule
A person used to receive, move, or withdraw stolen funds on behalf of criminals.
Carding
Fraud involving stolen payment-card information, compromised accounts, or related financial data.
Ripper
A criminal who scams other criminals, often by taking payment without delivering the promised goods or service.
A reminder that almost every “assassin for hire” post you see on the dark web is one of three things
1. an outright scam
2. a law-enforcement trap
3. teenagers discovering Tor for the first time
The only person in real danger is usually the one placing the order.
Over the years, hacking on the dark web has changed.
It used to be about finding technical weaknesses and breaking into systems. Today, attackers can simply buy or bribe their way in.
Instead of spending days planning an attack, they can buy stolen employee usernames and passwords, Slack or Teams access, or cloud credentials like AWS logins.
→ In 2022, Uber said an attacker likely bought a contractor’s corporate password on the dark web and used it to access internal systems, including Slack.
→ In 2024, attackers targeted companies using Snowflake by logging in with usernames and passwords that had already been stolen from employees’ computers and circulated online.
If your user’s password has already appeared in known data breaches, tell them before they create their account.
Passwords are immediately hashed using SHA-1 and then checked using k-anonymity. Only the first five characters of the hash are used for the lookup. Plaintext passwords and full hashes are never stored.
Try 500 passwords for at no cost: https://t.co/k3JKB6CMQm
In Nov 2026, Encrata will launch a suite of dark web lookup products.
Detailed job description: https://t.co/UJCJOZIqCt
^^^
These products will help businesses with multiple use cases:
→ Find leaked API keys on onion sites, private Telegram channels, private signal groups, shadow marketplaces, et al.
→ Financial institutions can find leaked credit card numbers and stolen ID documents
→ Banks can flag transactions linked to criminal marketplaces
→ Law firms can trace hidden assets
→ Enterprises can detect data being stolen before vendors report the incident
^^^
What we're looking for in candidates:
+ Thinks like an investigator and can turn a chaotic data swamp into clear product strategy
+ 0 to 1 builder who does not need an inherited playbook
+ Obsessed with data hygiene and data visualization
+ Can communicate equally well with the OSINT community, engineers, AI and customers
+ Has a strong ethical compass and understands that being technically possible does not automatically make something a good idea.
++ Brownie point if you know who Tufte is.
Gravatar for email validation
This forgotten piece of internet infrastructure can still provide surprisingly useful signals about whether an email address is real.
^^^
(1/6) Remember Gravatar?
Gravatar was founded in 2004 by Tom Preston-Werner, who later also co-founded GitHub.
WordPress acquired it in 2007.
It was (is, but no one uses it anymore) a service that lets you link a profile picture and basic info like name, DoB, etc., to your email address, so when you use that email on other websites, your details appear automatically.
Kind of like when you sign up with Gmail, you port your basic profile info, like your display picture, name, et al.
(2/6) Gravatar had an unprecedented scale by 2012 standards
Gravatar was serving more than 100,000 requests per second (8.6 billion per day) across millions of WordPress sites, GitHub, Stack Overflow, and Trello.
By 2015, there were > 200 million active users.
(3/6) Email validation angle
It is quite straightforward to check whether an email address uses Gravatar.
Simply convert an email address to its MD5 hash, then run it through this endpoint.
https://t.co/BB5B6D4ZNV{hash}
(4/6) Why it's useful
If a Gravatar profile is available for an email address, it essentially means that sometime between 2004 and 2015, a real human (not many bots at that time) created a Gravatar account and added their details.
A Gravatar profile does not prove that an email is currently deliverable. But it substantially increases the probability that the address belongs to a human, or once did.
(5/6) The caveats
→ Many of the email addresses are starter emails like "[email protected]". People move away from those as they grow older.
→ Business emails with a Gravatar account are a weak indicator because it's been 20 years. People move on from jobs, and companies cease to exist.
(6/6) Summary data
We scanned 270 million emails and found that 3% had a Gravatar account.
→ Those that had a Gravatar account were almost 3.5x more likely to be valid, deliverable emails.
→ Gmail accounts that have a Gravatar account are 14x more likely to be valid, deliverable emails.
The internet is full of forgotten signals. Encrata finds them, tests them at scale, and turns them into useful APIs.