14 ms·
Project Svalbard: The Future of Have I Been Pwned
- elamje 7y agoTroy is an awesome guy and I’m really happy that HIBP is outgrowing him to get more support, datasets, and features. I hope Have I Been Pwned goes to the right people and they do an even better job at moving it forward! Kudos Troy
- reallydontask 7y agoIt's a shame as this is likely to mean that we end up with a worse service, but completely understandable. hopefully, I will be proven wrong
- ComodoHacker 7y agoI wish you luck, Troy! Just don't sell it to some data mining/ad company.
- GordonS 7y agoI'd love to see a non-profit organisation like Mozilla pick this up, but that's obviously going to mean a lot less money going to Troy. OTOH, it's kind of difficult to begrudge Troy gaining financially from HIBP, since he's spent years building it up and has helped increase security awareness for so many people.
- cknight 7y agoGiven Mozilla's current direction in terms of looking for more revenue streams, it might be quite well timed - if it can be commercialized successfully on the B2B end, that is. https://www.translatetheweb.com/?from=&to=en&a=https://t3n.de/news/mozilla-ceo-chris-beard-anbieten-1168614/3/ https://www.translatetheweb.com/?from=&to=en&a=https://t3n.d...
- tomglynch 7y agoMozilla also recently launched their own version of HIBP that just gets the data from HIBP and passes it to their users: https://monitor.firefox.com/ https://monitor.firefox.com/ Though just realised, they're not that upfront about giving HIBP credit - If I were Troy this would peeve me a bit.
- lol768 7y agoIt's not massively advertised on the homepage (though in some respects, I think outside of infosec circles "Firefox Monitor" probably sounds more professional/neutral than "Have I been pwned"). I think they discussed HIBP in the launch announcement: https://blog.mozilla.org/security/2018/11/14/when-does-firefox-alert-for-breached-sites/ https://blog.mozilla.org/security/2018/11/14/when-does-firef... It's also in the FAQ: https://support.mozilla.org/en-US/kb/firefox-monitor-faq https://support.mozilla.org/en-US/kb/firefox-monitor-faq
- luag 7y agoJust tried it, they specifically write "Breach data provided by Have I Been Pwned" at the end of results.
- flurdy 7y agoI thought the same when I initially was prompted about Firefox monitor at the bottom of Firefox's new tab page. Was a little peeved at what seemed like a copy, but I have now realised it is just building on top of Troy's work [1] which is even better because of Firefox's larger reach. They don't have to have a blinking marque text at the top attributing it to Have I Been Pwned. But they could have mentioned it on the front page somewhere that HIBP is one of their main sources. I trust HIBP, therefore, more value to Firefox Monitor had I known that link. [1] https://www.troyhunt.com/were-baking-have-i-been-pwned-into-firefox-and-1password/ https://www.troyhunt.com/were-baking-have-i-been-pwned-into-...
- Vinnl 7y ago> I trust HIBP, therefore, more value to Firefox Monitor had I known that link. If you trust HiBP, you don't really need Firefox Monitor. It was created specifically to reach people that HiBP could not reach.
- peterburkimsher 7y agoI feel like Mozilla is well-positioned to meet Troy's requirements. It won't be cheap for them, but I think their branding is much more in line with his goals than the large FAANG tech companies. It makes sense to tie it into the Firefox Account password manager too. Mozilla could leverage Troy's close connections with industry to have Firefox as the recommended secure & open-source option for enterprise clients. Something that hasn't been touched on as much is the limitations that come with contracts for large commercial companies. Side projects are often expressly forbidden. Yes, Google with give you 20% time to work on your own ideas, but you can't then upload it to your personal website and call it your own - it becomes company property and may never see the light of day. I imagine that Mozilla are more open-minded in that respect. They also have plenty of experience with remote teams, which would work well for his family/travel tradeoffs. Please, Mozilla - if this opportunity is offered to you, take it.
- pbhjpbhj 7y agoNo, this shouldn't be used to segregate browsers. You just end up cutting a tonne of people of from the benefit unless the subscribe to the "we're sending all your DNS calls to third-parties and installing plugins you can't remove to advertise stuff you don't want"-browser.
- tomglynch 7y agoTroy works with Microsoft currently, so I doubt it would work with Mozilla as MS have Edge
- nandipmakwana 7y agoMicrosoft Regional Director don't work for Microsoft. If that's what you are referring to. They are recognized by Microsoft based on one's expertise & skills.
- tomglynch 7y agoAh yes, my mistake.
- pbhjpbhj 7y agoHIBP only works because of trust in Troy Hunt, few organisations have that. Maybe an organisation not involved in advertising at any level.
- GordonS 7y agoIt's definitely trust in Troy, and the level of transparency he's maintained, that have led to HIBP being successful. But I, personally, would now trust Mozilla with this, were there to take ownership.
- OskarS 7y agoI was just thinking, the only ones I can imagine taking ownership would be one of the "big internet foundations" that have earned their trust: Mozilla, the Internet Archive, Wikimedia, or the EFF. Of those, Mozilla and the EFF are the only ones that make real sense. I hope it's one of them, and not fucking Norton AntiVirus or whatever.
- GordonS 7y agoI agree about EFF - I'd be happy with Mozilla or EFF.
- duxup 7y agoCould they leverage some sort of Troy partnership / oversight? "Troy Approved!" Mozilla is a good group, they've had missteps but I find them trustworthy and the combination would be pretty trustworthy IMO.
- ygjb 7y agoA Mozilla acquisition of HIBP could look alot like Mozilla buying HIBP from them, and then bringing Troy on board for a period of time as an evangelist, and the nature of being an open source, community focused org means that Troy could retain his ties to Mozilla as long as he wants to, as a staff member or volunteer. I don't know how much has changed since I left Mozilla, but there were, and probably still are, a number of former employees and volunteer contributors that had a great degree of influence and input on various projects. Heck, Troy might even be a good potential addition to the Mozilla board of directors at some point in the future.
- WorldMaker 7y agoI also think that HIBP is something of a "public good" and would be best for some sort of non-profit or another. Mozilla is possibly the best currently aligned, of course. Another weird thought is that it's the sort of "baseline infrastructure" that should be "governmental" to the internet. Unfortunately the closest I can think to an existing model for that is ICANN and that may not be something to emulate.
- arkitaip 7y agoThis is really public utility work and should be treated like it instead of a for-profit project. Many thanks to Troy for his hard work over the years for making the internet a safer place.
- pbhjpbhj 7y agotl;dr He's realised he's the single point of failure, can't do it all himself, wants to balance work & family. Doesn't want the work/cost of hiring people and making a business. So, he's preparing to sell it and there's a wishlist of what he'd like the new owner to do. Did I get it all?
- jsmeaton 7y agoAlso he’ll stay on as part of the package.
- ujoh1 7y agoHello See how you can make a steady passive incomes of $100 daily on virta stock trading without you risking your money and your investment visit the website here http://www.virtatrade.com/index.php http://www.virtatrade.com/index.php for more details
- cm2187 7y agoI cannot say enough praises of Troy and HIBP. But it is a risky operation. I understand HIBP derives its value from grey-ish hats sharing with Troy any leaked dataset they find because they know him or because of his reputation. If he leaves, it is not clear to me that his trust and reputation will stay behind with the company running HIBP. The minute HIBP ceases to be the central place for these new datasets to be shared, it ceases to be of any practical use.
- GordonS 7y agoSomething to keep in mind is that the datasets being shared with Troy are almost all already available on underground forums, some openly, some for sale.
- jfdhu 7y agoAnd whilst its impossible to police effectively the datasets on various forums, it seems KPMG and Troy Hunt are just not aware of the fact that GDPR exists. https://en.wikipedia.org/wiki/General_Data_Protection_Regulation https://en.wikipedia.org/wiki/General_Data_Protection_Regula... Its quite interesting putting in various peoples email addresses to see what sites they are linked to. Maybe once he has made some money out of it, a GDPR claim and financial settlement can be made as he's made no steps to control the data privacy of Europeans.
- paublyrne 7y agoDoes this really fall foul of GDPR? I would have guessed that once your data is in the wild, there is nothing in GDPR that applies. GDPR puts certain responsibilities on groups you give your data to treat that data in certain ways in terms of who it is shared with, which would not seem to apply to someone offering a lookup of an in the wild dataset. I'm curious if my naive understanding of this is wrong.
- addicted 7y agoI’m not sure how GDPR applies to HIBP. GDPR is all about data that is shared by the user. But HIBP is about data that hasn’t been shared by a user, but rather, is available publicly. It’s a grey area at the very least.
- trollied 7y agoI'd like to see Let's Encrypt step up and run this service. Seems like a natural fit.
- peterburkimsher 7y agoProtonMail/ProtonVPN would also be a good fit, but I doubt they could afford it.
- computerfriend 7y agoWhy would they be a good fit?
- _underfl0w_ 7y agoJust because they're tangentially related to infosec in some way doesn't mean they'd be a good fit. IIRC aren't there actually privacy concerns regarding Proton? That may just be FUD. Plus, I doubt they would maintain the level of transparency we've come to expect from HIBP. They don't seem very... transparent.
- chaitanya 7y agoMany people here assuming that Troy Hunt will leave HIBP after selling it. He explicitly mentions that he will remain a part of it: > I'll remain a part of HIBP. I fully intend to be part of the acquisition, that is some company gets me along with the project. HIBP's brand is intrinsically tied to mine and at present, it needs me to go along with it.
- 7ewis 7y ago> at present
- deleted 7y ago[deleted]
- flurdy 7y agoHIBP has little value without Troy, so he has to come as part of the package. But for his own well-being over time he needs to delegate and divest himself as the single bus factor for HIBP. But that does not have to happen instantly and can be gradual without affecting the value of HIBP (in money and usefulness for us). Whoever purchases HIBP also knows this. And as with most acquisitions, they eventually oust the founders. But for it to be successful it is after a long time when it has properly matured into an organisation.
- thieving_magpie 7y agoI understand his intent. This just isn't my first rodeo. It's not uncommon for there to be talk of grand intentions to stay on and lead after acquisition. It rarely works out that way.
- jedberg 7y agoTL;DR: Have I Been Pwned is for sale and is being renamed Project Svalbard. Troy is looking for buyers that will keep the service free, and he'll go work with the buyer.
- shedside 7y agoAIUI, “Project Svalbard” is the name of the project to find a new home for HIBP. The actual service isn’t being renamed (yet).
- GordonS 7y agoIt is indeed common to have a "project name" when buying/selling a company - but in my experience that has always been largely for reasons of secrecy, so it is a bit odd in this case.
- dhruvrrp 7y agoHIBP could be an excellent B2B offering for companies. Imagine someone like Microsoft offering it as an addon to their business clients to improve security practices. Or a more independent company offering it as a standalone service, kinda like Mozilla (Monitor) or even something like Symantec (tho they seem to be bleeding money recently)
- onli 7y agoBut we see that so often. The original founder of a thing has a list of requirements he wants met, he wants to stay onboard. But then stuff happens and the buyer uses his control. Think Instagram, Whatsapp, Tumblr(?) - there are thousand examples. I'd hope Troy reconsidered the "just create a business yourself" solution. That could be structured in a way that makes sure the trust Troy earned stays linked to the project. And a bootstrapped company starting from the profitable position I assume HIBP is in now (with the business deals) does not at all have to mean more work for him. He could just offload the work he can't handle anymore to employees. An acquisition to anyone not as trustworthy as the current solution/the candidates like Mozilla mentioned here would be a disaster mid to longterm.
- jagermo 7y agoI understand Troy, especially his fear of a burnout. That's no joke. I think there are several interesting companies, besides Mozilla. I could see F-Secure making an offer. HIBP ticks a lot of boxes when it comes to business security, password reuse beeing a big issue there. Mikko and his team have a proofen track record and are well connected in the grey-hat area. Plus, they are in Finnland, near to Norway :)
- jdboyd 7y agoIf F-Secure is in Finnland, doesn't that mean they would have to delete user data on demand, undermining the service in doing so?
- chipperyman573 7y agoI wonder if you just have passwords and don't link them to usernames, then that wouldn't be "your data" because it can't be connected back to you?
- davidhyde 7y agoUndermine the service for who? The person who asked to have their data removed or the company who is interested in data about a specific person. If the answer is the latter then I think its fair that the person can ask to have their information removed. I think that Troy understands this distinction too and I also hope that HIBP remains that way.
- nebulous1 7y agoI missed this verifications.io story and it appears that my personal email address was in the breach. Is there any way of knowing whether or not other data was associated with my listing? DOB etc.
- deleted 7y ago[deleted]
- skc 7y agoHe's still a Microsoft employee is he not? Wonder if he couldn't just bring it in-house?
- ptman 7y agoWhen has he ever worked for Microsoft? https://www.linkedin.com/in/troyhunt/ https://www.linkedin.com/in/troyhunt/ https://www.troyhunt.com/microsoft-regional-director/ https://www.troyhunt.com/microsoft-regional-director/ - "I’m not going to work for Microsoft and despite the title of “Microsoft Regional Director”, I’m no more an employee than what I was (and still am) an MVP"
- skc 7y agoAhh, the title has always thrown me off.
- andimm 7y agoHe was not a Microsoft employee. He is a MVP but worked for Pfizer iirc. Now he is with Pluralsight.
- sschueller 7y agoCan we move the project into a blockchain and run it on IPFS? EDIT: Serious question, generate hashes out of the leaked logins, store them in a blockchain and provide an interface for lookup via IPFS. Those credentials are considered burned anyway so storing them for ever in a blockchain won't matter. Being in a blockchain anyone can access the data and use them for example on a registration page.
- SmellyGeekBoy 7y agoHN has warped my view on these things so much that I'm not sure whether this is a genuine question or some kind of inside joke?
- GordonS 7y agoWhat value would a blockchain add here over a database?
- t0liman 7y agoA breach-monitoring service could act as a data washing service, sic. Especially if privatized. Blockchain is Very overrated, but it could be useful in keeping data "safe" where the temptation would exist to index or obscure results. Especially where data collection and censoring / disclosure has value to certain markets, i.e. Timed/rated or delayed disclosure, sic. IDK, it's not impossible, but it's not my wheelhouse either. I don't see any reuse or value to old databases and hashes being public, so it's missing that purpose to exist or be used/shared. Like a lot of blockchain is. It's not enough to exist, it has to be shared and kept alive. I suppose. Still, If you look at the way AV and user security is handled, there are potential vectors to prevent or anticipate, especially if the process of disclosure is censored or segregated. Perhaps also if they proactively lean towards purges or spontaneous negative actions, in order to obscure their intent or actual content / behavior. HIBP relies on disclosure, and if it were woven into a typical service structure, there would be a temptation to "alleviate" the workload for customers, offering to "feed the beast" with positive results and competitive, defensive tactics against 3rd parties offering a similar product. Which could segment the disclosure process, so that you would have multiple options, much the way that AV and Malware is handled. And now you have the same failures as AV and Malware being segmented domains. The probability of a corporation being incentivized to airbrush a 3rd party listing in a semi-corporate "index" or offering "alternatives" to anxious, very large corporations to disclosure or remediation. Especially if they deal with financial or legal data, or specific disclosure requirements. And have problems with timely disclosure, or any disclosure. Imagine if a clearing house for disclosure existed as a Symantec or Kaspersky "Subscription", with tiers of access and disclosure prevention for corporate members, wrapped up in a daily routine app, such as a 2FA/Password manager. So that a disclosure would be made silently by the subscription service, without disclosing details, or the level of breach, etc. The accounts or corporations breached, would just have their entire client accounts auto-reset and the updated password would be applied to your password manager within a batch process without the user(s), the press, the security agencies, or the hacker(s) being notified. That, instead of revealing the time period, the hashes of usernames & passwords, or the name of the user, or their IDs, it would just be rotated on a regular basis, and invisibly managed. Its a concept with some value, ie "paranoid" security features as a service, to prevent or anticipate disaster, sic. But handled via a handshake type batch process of cycling password management. But this also has potential for occlusion and obfuscation, especially in examples where the breach would be a crime, or need to be disclosed to federal/state/police agencies, etc. Thankfully, most security policy would prevent this kind of amorphous takeover, but for small businesses and large businesses, having access security taken away and handled by 3rd parties, for convenience, is inevitable.
- w8rbt 7y agoI hope that the SHA1 hashes remain freely available for download. I use them to build a bloom filter for password vetting. We should all do away with password complexity rules (except minimum length) and simply test a large, comprehensive exposed password bloom filter for membership. It's very fast (constant time) and efficient and if the test returns no, then it's safe for a user to select that password. Here's the code: https://github.com/w8rbt/bp https://github.com/w8rbt/bp Also note that this approach satisfies the updated (June 2017) NIST 800-63-3B password vetting guidelines.
- ttt111222333 7y agoCool! I did something similar. First I used a bloom filter then a golomb set. https://github.com/terencechow/pwnedpasswords https://github.com/terencechow/pwnedpasswords
- w8rbt 7y agoVery nice. I've never used a Golomb Set (looks interesting). I bet we'll see more organizations doing this and maybe in five to ten years, it'll be the norm.
- fjsolwmv 7y agoThat doesn't work, because of hunter2 is in the PW database but hunter3 isn't, your system will think hunter3 is secure even though it's not.
- noisy_boy 7y agoI think it should be two step - checking against the list and if that passes, complexity check. Covers complex passwords that are known to have been in use/leaked and non-complex ones too.
- ga-vu 7y agoSo why was the owner of LeakedSource arrested and charged, and this guy isn't? He did the same thing. Only instead of selling to hackers, he sold our hacked data to companies and governments.
- giorgioz 7y agoI sense trolling
- ga-vu 7y agoThanks for the downvotes. Glad you can't see through this guy's marketing BS.
- TheHypnotist 7y agoDoes HIBP sell the raw data?
- Ajedi32 7y agoNope. Though I suppose if HIBP itself were acquired, that would presumably include the raw data?
- temptemptemp111 7y agoYep. I have a client that is working on arresting someone who uploaded all of their customer data to this guy's website. None of them will answer - it seems like they only care about money and their operation just benefits the big companies. Most small businesses don't have the resources to completely security proof their custom services against these $3K+ hacking tools that the script kiddies use (who steal data and upload it to Troy's services).
- jstarfish 7y agoI agree with your sentiment, but there is the difference in criminal intent with the former. It's legal to sell armor piercing bullets, but marketing them as "cop killers" will not fly.
- giorgioz 7y agowasn't HIBP going to a B2B SaaS that you hook up at signup to forbid users to signup with an email/password combination that has already been leaked? I'm a SaaS owner, I would pay for that.
- bookofjoe 7y agoTotally off topic, but still...: Many years ago, the New York Times did a lengthy piece about the Svalbard Seed Repository, referring to it as being located on "the island of Svalbard." It took repeated emails/corrections/tweets by me before they finally corrected the story and noted "Svalbard is not an island, it is an archipelago." All subsequent references in the Times have got it right.
- bookofjoe 7y agoHere is the correction, published on April 22, 2010: https://archive.nytimes.com/query.nytimes.com/gst/fullpage-9F0CE6DF163EF931A15757C0A9669D8B63.html https://archive.nytimes.com/query.nytimes.com/gst/fullpage-9...
- bookofjoe 7y agoHere is the (corrected) original article — with correction appended — published on April 15, 2010: https://archive.nytimes.com/query.nytimes.com/gst/fullpage-9402E4DA1238F936A25757C0A9669D8B63.html https://archive.nytimes.com/query.nytimes.com/gst/fullpage-9...
- twayback 7y agoHow is making money from stolen data legal? My email address is in the database and I never consented to it. Is there no legal repercussion?
- temptemptemp111 7y agoYa it sucks. I had a client whose data was stolen and uploaded to his site. He wouldn't reply to me... He works for Microsoft and his operation mostly benefits the big companies - and can really damage a small company that happened to start out with bad software.
- vermilingua 7y agoWorth mentioning that the value of HIBP is largely based on trust in Troy Hunt. I think he’s an incredible guy who does incredible work; but he’s also an Australian citizen. Due to our new surveillance laws, he could be forced to backdoor HIBP, or more likely, Pwned Passwords. This is possibly a step by Troy to mitigate that risk, and given his position I’m surprised he didn’t mention that at all in this post.
- TimTheTinker 7y agoI think Troy probably has more than enough social credit to simply ask for help on Twitter and receive pro-bono legal representation if regulators somehow embarked on a misguided attempt to target him or HIBP.
- paranoidrobot 7y agoWhat would backdooring HIBP achieve? It's not a repository or method of communications.
- vermilingua 7y agoPwned Passwords uses tricky crypto to make sure his service never sees your full password. He could use trickier crypto to make sure that it does.
- paranoidrobot 7y agoI think that's a bit of a reach. That's all client/requester side, which has been implemented on third party sites/services. There'd be a lot of questions raised if suddenly it required that you use a different technique. A more subtle and (IMO) more realistic variant would be to backdoor the javascript to capture all input on that site instead. But you have to ask yourself - who would be the government target, in that case? They'd have to: - Have a technically sophisticated target where the government doesn't know their password, and is unable to otherwise break their security (eg forcing Google/Apple/Microsoft/etc to do the work, cloning devices, regular surveilance) - Have that same target also regularly test their passwords against a password strength meter on the public webpage. - Be willing to risk a public leak that this was happening. I don't think that anyone who meets the first point would be stupid enough to meet the second. I mean, sure, people make plenty of dumb mistakes - but surely not that one, repeatedly.
- ThinkBeat 7y agoI hope that other companies will still be able to query to the database for free. 1Password does it now and I like it.
- brightball 7y agoBest of luck Troy and keep up the good work!
- djee 7y agoI guess he's feeling the heat of sites that do more than parsing emails from SPAM lists. These sites include full cracked passwords, HIBP 2.0, see e.g. https://scatteredsecrets.com/ https://scatteredsecrets.com/.
- runjake 7y agoGood luck to Troy. The money would be really good, but hopefully for the rest of us, he doesn't sell to Cisco. Or Oracle, or any other mega corps that buy and nerf the usefulness of the product.
- dreamcompiler 7y agoBrewster Kahle, are you here? This seems like something in your wheelhouse.
- AngeloAnolin 7y agoI understand why Troy is doing this. Security is a big and a complex endeavor and having majority of the stuff done by himself alone is taking a toll. One option that Troy could have done is to spin up a team / small company that would continue this project - with full control and guidance under his direction. That way, the trust that he has built from everyone at the community will be carried forward as the project progresses and matures further. This will also allow visibility and transparency knowing that the people who would be working on this project will have access to him and everyone is on board on the direction moving forward. Lots of companies / venture capitalists would be willing to support this cause which could provide the financing the project will need to be sustained and grow further.
- therealdrag0 7y agoSo many people saying the value of HIBP is the trust in Troy Hunt. But surely I'm not the only one that has used the service for years (and shared it with friends) without knowing anything about Troy Hunt...
- TimTheTinker 7y agoSocial credit and trust has a way of naturally propagating. Trust, beliefs, even world views are more often "caught" than deliberately and carefully chosen -- to the detriment of many. All it takes is a few liars with the appearance of trustworthiness to spread false beliefs very widely. Note, my comment is not about Troy. Security-wise, I think the trust he carries is well-deserved.
- vxNsr 7y agoThe trust is coming from infosec people who are sharing their datasets with him, not really from users.
- parliament32 7y agoSummary: Troy is bored so he's selling out. Great.
- paranoidrobot 7y agoI don't think it's fair to call someone who's clearly stressed and close to burnout 'bored'.
- OJFord 7y agoIn some ways, wouldn't it be great if the internet had evolved with, analogously to DNS, 'User Name Servers', like a sort of global distributed IAM? Leak monitoring would be a service provided by the UNS, not falling to a volunteer, and credential revocation could be automatic and immediate. I suppose we sort of have that bolted on with OpenID/OAuth, but that's still 'choose a provider' rather than 'this is the one way', with many servers run by different entities, but one 'system'.
- deleted 7y ago[deleted]
- jimktrains2 7y agoIt's existed since 1988: LDAP/X.500[1] It's just not used globally because of three reasons, as far as I can tell, 1) most people don't want their information public and searchable to that extent 2) most orgs _want_ to silo you in or otherwise control your account 3) the org using x500 still needs to have their own permissions separate from the central directory, which is the harder part of auth[nz], so just rolling your own authn is often easier. [1] https://en.wikipedia.org/wiki/X.500 https://en.wikipedia.org/wiki/X.500
- OJFord 7y agoAh yes, and Shibboleth is another I should've thought of in earlier comment. I think you're absolutely right in particular with #2. But if it had come originally, alongside DNS, 'everything has an address, everyone has an identity', it might've been an unquestionable fact of the internet. Orgs can't silo you in to their alternate net where they have a more desirable domain name, because it's just not practical or user friendly. I just think it might have been so for user identity.
- fjsolwmv 7y agoThe critical flaw (for users) of Oauth is that there is no portability between providers. Unlike a domain name, You can't move your login ID to a different provider
- fanf2 7y ago
- Calib3r 7y agoIt pains me to see how many posters on this thread are not aware of the leakedsource (.ru, .co, etc.) websites that show the exact thing HIBP shows, except with a much higher fidelity.
- dheera 7y agoI came here hoping it was something about Svalbard. I went there a couple years ago in the dead of winter. It's an amazing place.
- Ayesh 7y agoTell us more! I'm planning for a longyearbien/svalbard trip towards the end of this year or summer next year.
- dheera 7y agoSure, what do you want to know? I went in the dead of winter, so might be a little different from what you might experience in summer. https://www.facebook.com/dheera/media_set?set=a.10101091792964948&type=3 https://www.facebook.com/dheera/media_set?set=a.101010917929...
- ddffre 7y agoHis blog is really good, I have enjoyed reading his other posts as well.
- yhoiseth 7y agoMaybe relevant for Stripe? Based on their acquisition of Indie Hackers, it seems like they’re adept at this kind of acquisition. And online security contributes to their goal of increasing “the GDP of the internet.“
- twayback 7y agoGuys whats the fuss about -- its just a stupid database - anyone can make this by scraping hacker spoil dumps available on the internet.