Live data from Hacker News

Project Svalbard: The Future of Have I Been Pwned

troyhunt.com

11–20 of 160 posts

Re: Project Svalbard: The Future of Have I Been Pwned

#12
post #5

I'd love to see a non-profit organisation like Mozilla pick this up, but that's obviously going to mean a lot less money going to Troy. OTOH, it's kind of difficult to begrudge Troy gaining financially from HIBP, since he's spent years building it up and has helped increase security awareness for so many people.

I feel like Mozilla is well-positioned to meet Troy's requirements. It won't be cheap for them, but I think their branding is much more in line with his goals than the large FAANG tech companies.

It makes sense to tie it into the Firefox Account password manager too. Mozilla could leverage Troy's close connections with industry to have Firefox as the recommended secure & open-source option for enterprise clients.

Something that hasn't been touched on as much is the limitations that come with contracts for large commercial companies. Side projects are often expressly forbidden. Yes, Google with give you 20% time to work on your own ideas, but you can't then upload it to your personal website and call it your own - it becomes company property and may never see the light of day. I imagine that Mozilla are more open-minded in that respect. They also have plenty of experience with remote teams, which would work well for his family/travel tradeoffs.

Please, Mozilla - if this opportunity is offered to you, take it.

Re: Project Svalbard: The Future of Have I Been Pwned

#14
post #5

I'd love to see a non-profit organisation like Mozilla pick this up, but that's obviously going to mean a lot less money going to Troy. OTOH, it's kind of difficult to begrudge Troy gaining financially from HIBP, since he's spent years building it up and has helped increase security awareness for so many people.

HIBP only works because of trust in Troy Hunt, few organisations have that.

Maybe an organisation not involved in advertising at any level.

Re: Project Svalbard: The Future of Have I Been Pwned

#15
post #5

I'd love to see a non-profit organisation like Mozilla pick this up, but that's obviously going to mean a lot less money going to Troy. OTOH, it's kind of difficult to begrudge Troy gaining financially from HIBP, since he's spent years building it up and has helped increase security awareness for so many people.

I feel like Mozilla is well-positioned to meet Troy's requirements. It won't be cheap for them, but I think their branding is much more in line with his goals than the large FAANG tech companies. It makes sense to tie it into the Firefox Account password manager too. Mozilla could leverage Troy's close connections with industry to have Firefox as the recommended secure & open-source option for enterprise clients. Som…

No, this shouldn't be used to segregate browsers. You just end up cutting a tonne of people of from the benefit unless the subscribe to the "we're sending all your DNS calls to third-parties and installing plugins you can't remove to advertise stuff you don't want"-browser.

Re: Project Svalbard: The Future of Have I Been Pwned

#16
post #9

Earlier quoted context omitted.

Given Mozilla's current direction in terms of looking for more revenue streams, it might be quite well timed - if it can be commercialized successfully on the B2B end, that is. https://www.translatetheweb.com/?from=&to=en&a=https://t3n.d...

Mozilla also recently launched their own version of HIBP that just gets the data from HIBP and passes it to their users: https://monitor.firefox.com/ Though just realised, they're not that upfront about giving HIBP credit - If I were Troy this would peeve me a bit.

It's not massively advertised on the homepage (though in some respects, I think outside of infosec circles "Firefox Monitor" probably sounds more professional/neutral than "Have I been pwned").

I think they discussed HIBP in the launch announcement: https://blog.mozilla.org/security/2018/11/14/when-does-firef...

It's also in the FAQ: https://support.mozilla.org/en-US/kb/firefox-monitor-faq

Re: Project Svalbard: The Future of Have I Been Pwned

#17
post #5

I'd love to see a non-profit organisation like Mozilla pick this up, but that's obviously going to mean a lot less money going to Troy. OTOH, it's kind of difficult to begrudge Troy gaining financially from HIBP, since he's spent years building it up and has helped increase security awareness for so many people.

HIBP only works because of trust in Troy Hunt, few organisations have that. Maybe an organisation not involved in advertising at any level.

It's definitely trust in Troy, and the level of transparency he's maintained, that have led to HIBP being successful.

But I, personally, would now trust Mozilla with this, were there to take ownership.

Re: Project Svalbard: The Future of Have I Been Pwned

#18
post #8

I cannot say enough praises of Troy and HIBP. But it is a risky operation. I understand HIBP derives its value from grey-ish hats sharing with Troy any leaked dataset they find because they know him or because of his reputation. If he leaves, it is not clear to me that his trust and reputation will stay behind with the company running HIBP. The minute HIBP ceases to be the central place for these new datasets to be s…

Something to keep in mind is that the datasets being shared with Troy are almost all already available on underground forums, some openly, some for sale.

Re: Project Svalbard: The Future of Have I Been Pwned

#19
post #8

I cannot say enough praises of Troy and HIBP. But it is a risky operation. I understand HIBP derives its value from grey-ish hats sharing with Troy any leaked dataset they find because they know him or because of his reputation. If he leaves, it is not clear to me that his trust and reputation will stay behind with the company running HIBP. The minute HIBP ceases to be the central place for these new datasets to be s…

I share your concern. This is similar to many problems in the InfoSec community which can not simply be solved by a corporation by throwing money at them but instead require long-term cultivation of contacts, trust and expertise by a few / single individuals, something that money can't buy.

Re: Project Svalbard: The Future of Have I Been Pwned

#20
post #5

I'd love to see a non-profit organisation like Mozilla pick this up, but that's obviously going to mean a lot less money going to Troy. OTOH, it's kind of difficult to begrudge Troy gaining financially from HIBP, since he's spent years building it up and has helped increase security awareness for so many people.

I feel like Mozilla is well-positioned to meet Troy's requirements. It won't be cheap for them, but I think their branding is much more in line with his goals than the large FAANG tech companies. It makes sense to tie it into the Firefox Account password manager too. Mozilla could leverage Troy's close connections with industry to have Firefox as the recommended secure & open-source option for enterprise clients. Som…

Troy works with Microsoft currently, so I doubt it would work with Mozilla as MS have Edge
Post reply on HN