Live data from Hacker News

Project Svalbard: The Future of Have I Been Pwned

troyhunt.com

21–30 of 160 posts

Re: Project Svalbard: The Future of Have I Been Pwned

#21
Many people here assuming that Troy Hunt will leave HIBP after selling it. He explicitly mentions that he will remain a part of it:

> I'll remain a part of HIBP. I fully intend to be part of the acquisition, that is some company gets me along with the project. HIBP's brand is intrinsically tied to mine and at present, it needs me to go along with it.

Re: Project Svalbard: The Future of Have I Been Pwned

#22
post #9

Earlier quoted context omitted.

Given Mozilla's current direction in terms of looking for more revenue streams, it might be quite well timed - if it can be commercialized successfully on the B2B end, that is. https://www.translatetheweb.com/?from=&to=en&a=https://t3n.d...

Mozilla also recently launched their own version of HIBP that just gets the data from HIBP and passes it to their users: https://monitor.firefox.com/ Though just realised, they're not that upfront about giving HIBP credit - If I were Troy this would peeve me a bit.

Just tried it, they specifically write "Breach data provided by Have I Been Pwned" at the end of results.

Re: Project Svalbard: The Future of Have I Been Pwned

#23

Earlier quoted context omitted.

I feel like Mozilla is well-positioned to meet Troy's requirements. It won't be cheap for them, but I think their branding is much more in line with his goals than the large FAANG tech companies. It makes sense to tie it into the Firefox Account password manager too. Mozilla could leverage Troy's close connections with industry to have Firefox as the recommended secure & open-source option for enterprise clients. Som…

Troy works with Microsoft currently, so I doubt it would work with Mozilla as MS have Edge

Microsoft Regional Director don't work for Microsoft. If that's what you are referring to. They are recognized by Microsoft based on one's expertise & skills.

Re: Project Svalbard: The Future of Have I Been Pwned

#24
post #9

Earlier quoted context omitted.

Given Mozilla's current direction in terms of looking for more revenue streams, it might be quite well timed - if it can be commercialized successfully on the B2B end, that is. https://www.translatetheweb.com/?from=&to=en&a=https://t3n.d...

Mozilla also recently launched their own version of HIBP that just gets the data from HIBP and passes it to their users: https://monitor.firefox.com/ Though just realised, they're not that upfront about giving HIBP credit - If I were Troy this would peeve me a bit.

I thought the same when I initially was prompted about Firefox monitor at the bottom of Firefox's new tab page.

Was a little peeved at what seemed like a copy, but I have now realised it is just building on top of Troy's work [1] which is even better because of Firefox's larger reach.

They don't have to have a blinking marque text at the top attributing it to Have I Been Pwned. But they could have mentioned it on the front page somewhere that HIBP is one of their main sources. I trust HIBP, therefore, more value to Firefox Monitor had I known that link.

[1] https://www.troyhunt.com/were-baking-have-i-been-pwned-into-...

Re: Project Svalbard: The Future of Have I Been Pwned

#25

Many people here assuming that Troy Hunt will leave HIBP after selling it. He explicitly mentions that he will remain a part of it: > I'll remain a part of HIBP. I fully intend to be part of the acquisition, that is some company gets me along with the project. HIBP's brand is intrinsically tied to mine and at present, it needs me to go along with it.

> at present

Re: Project Svalbard: The Future of Have I Been Pwned

#27
post #18
post #8

I cannot say enough praises of Troy and HIBP. But it is a risky operation. I understand HIBP derives its value from grey-ish hats sharing with Troy any leaked dataset they find because they know him or because of his reputation. If he leaves, it is not clear to me that his trust and reputation will stay behind with the company running HIBP. The minute HIBP ceases to be the central place for these new datasets to be s…

Something to keep in mind is that the datasets being shared with Troy are almost all already available on underground forums, some openly, some for sale.

And whilst its impossible to police effectively the datasets on various forums, it seems KPMG and Troy Hunt are just not aware of the fact that GDPR exists. https://en.wikipedia.org/wiki/General_Data_Protection_Regula...

Its quite interesting putting in various peoples email addresses to see what sites they are linked to. Maybe once he has made some money out of it, a GDPR claim and financial settlement can be made as he's made no steps to control the data privacy of Europeans.

Re: Project Svalbard: The Future of Have I Been Pwned

#28

Many people here assuming that Troy Hunt will leave HIBP after selling it. He explicitly mentions that he will remain a part of it: > I'll remain a part of HIBP. I fully intend to be part of the acquisition, that is some company gets me along with the project. HIBP's brand is intrinsically tied to mine and at present, it needs me to go along with it.

[deleted]

Re: Project Svalbard: The Future of Have I Been Pwned

#29
post #27
post #18

Earlier quoted context omitted.

Something to keep in mind is that the datasets being shared with Troy are almost all already available on underground forums, some openly, some for sale.

And whilst its impossible to police effectively the datasets on various forums, it seems KPMG and Troy Hunt are just not aware of the fact that GDPR exists. https://en.wikipedia.org/wiki/General_Data_Protection_Regula... Its quite interesting putting in various peoples email addresses to see what sites they are linked to. Maybe once he has made some money out of it, a GDPR claim and financial settlement can be made a…

Does this really fall foul of GDPR? I would have guessed that once your data is in the wild, there is nothing in GDPR that applies. GDPR puts certain responsibilities on groups you give your data to treat that data in certain ways in terms of who it is shared with, which would not seem to apply to someone offering a lookup of an in the wild dataset.

I'm curious if my naive understanding of this is wrong.

Re: Project Svalbard: The Future of Have I Been Pwned

#30
post #8

I cannot say enough praises of Troy and HIBP. But it is a risky operation. I understand HIBP derives its value from grey-ish hats sharing with Troy any leaked dataset they find because they know him or because of his reputation. If he leaves, it is not clear to me that his trust and reputation will stay behind with the company running HIBP. The minute HIBP ceases to be the central place for these new datasets to be s…

> I'll remain a part of HIBP. I fully intend to be part of the acquisition, that is some company gets me along with the project. HIBP's brand is intrinsically tied to mine and at present, it needs me to go along with it.

He's made it pretty clear in the blog post that he intends to stay on and has acknowledged that his reputation plays an important part in making HIBP what it is.

Post reply on HN