Live data from Hacker News

Project Svalbard: The Future of Have I Been Pwned

troyhunt.com

31–40 of 160 posts

Re: Project Svalbard: The Future of Have I Been Pwned

#31
post #27
post #18

Earlier quoted context omitted.

Something to keep in mind is that the datasets being shared with Troy are almost all already available on underground forums, some openly, some for sale.

And whilst its impossible to police effectively the datasets on various forums, it seems KPMG and Troy Hunt are just not aware of the fact that GDPR exists. https://en.wikipedia.org/wiki/General_Data_Protection_Regula... Its quite interesting putting in various peoples email addresses to see what sites they are linked to. Maybe once he has made some money out of it, a GDPR claim and financial settlement can be made a…

> Maybe once he has made some money out of it, a GDPR claim and financial settlement

Do you think GDPR fines go to the person, and not the regulator?

Re: Project Svalbard: The Future of Have I Been Pwned

#32
HIBP could be an excellent B2B offering for companies. Imagine someone like Microsoft offering it as an addon to their business clients to improve security practices.

Or a more independent company offering it as a standalone service, kinda like Mozilla (Monitor) or even something like Symantec (tho they seem to be bleeding money recently)

Re: Project Svalbard: The Future of Have I Been Pwned

#33
post #27

Earlier quoted context omitted.

And whilst its impossible to police effectively the datasets on various forums, it seems KPMG and Troy Hunt are just not aware of the fact that GDPR exists. https://en.wikipedia.org/wiki/General_Data_Protection_Regula... Its quite interesting putting in various peoples email addresses to see what sites they are linked to. Maybe once he has made some money out of it, a GDPR claim and financial settlement can be made a…

Does this really fall foul of GDPR? I would have guessed that once your data is in the wild, there is nothing in GDPR that applies. GDPR puts certain responsibilities on groups you give your data to treat that data in certain ways in terms of who it is shared with, which would not seem to apply to someone offering a lookup of an in the wild dataset. I'm curious if my naive understanding of this is wrong.

I’m not sure how GDPR applies to HIBP. GDPR is all about data that is shared by the user. But HIBP is about data that hasn’t been shared by a user, but rather, is available publicly.

It’s a grey area at the very least.

Re: Project Svalbard: The Future of Have I Been Pwned

#34
post #17

Earlier quoted context omitted.

HIBP only works because of trust in Troy Hunt, few organisations have that. Maybe an organisation not involved in advertising at any level.

It's definitely trust in Troy, and the level of transparency he's maintained, that have led to HIBP being successful. But I, personally, would now trust Mozilla with this, were there to take ownership.

I was just thinking, the only ones I can imagine taking ownership would be one of the "big internet foundations" that have earned their trust: Mozilla, the Internet Archive, Wikimedia, or the EFF. Of those, Mozilla and the EFF are the only ones that make real sense. I hope it's one of them, and not fucking Norton AntiVirus or whatever.

Re: Project Svalbard: The Future of Have I Been Pwned

#35
But we see that so often. The original founder of a thing has a list of requirements he wants met, he wants to stay onboard. But then stuff happens and the buyer uses his control. Think Instagram, Whatsapp, Tumblr(?) - there are thousand examples.

I'd hope Troy reconsidered the "just create a business yourself" solution. That could be structured in a way that makes sure the trust Troy earned stays linked to the project. And a bootstrapped company starting from the profitable position I assume HIBP is in now (with the business deals) does not at all have to mean more work for him. He could just offload the work he can't handle anymore to employees.

An acquisition to anyone not as trustworthy as the current solution/the candidates like Mozilla mentioned here would be a disaster mid to longterm.

Re: Project Svalbard: The Future of Have I Been Pwned

#36
post #27
post #18

Earlier quoted context omitted.

Something to keep in mind is that the datasets being shared with Troy are almost all already available on underground forums, some openly, some for sale.

And whilst its impossible to police effectively the datasets on various forums, it seems KPMG and Troy Hunt are just not aware of the fact that GDPR exists. https://en.wikipedia.org/wiki/General_Data_Protection_Regula... Its quite interesting putting in various peoples email addresses to see what sites they are linked to. Maybe once he has made some money out of it, a GDPR claim and financial settlement can be made a…

They would just get hit back with tariffs, no problem. If I were European I wouldn't want to be playing money games with America.

Re: Project Svalbard: The Future of Have I Been Pwned

#37
post #8

I cannot say enough praises of Troy and HIBP. But it is a risky operation. I understand HIBP derives its value from grey-ish hats sharing with Troy any leaked dataset they find because they know him or because of his reputation. If he leaves, it is not clear to me that his trust and reputation will stay behind with the company running HIBP. The minute HIBP ceases to be the central place for these new datasets to be s…

> I'll remain a part of HIBP. I fully intend to be part of the acquisition, that is some company gets me along with the project. HIBP's brand is intrinsically tied to mine and at present, it needs me to go along with it. He's made it pretty clear in the blog post that he intends to stay on and has acknowledged that his reputation plays an important part in making HIBP what it is.

Which matters little, because it matters who the ultimate boss is.

Re: Project Svalbard: The Future of Have I Been Pwned

#39
post #27
post #18

Earlier quoted context omitted.

Something to keep in mind is that the datasets being shared with Troy are almost all already available on underground forums, some openly, some for sale.

And whilst its impossible to police effectively the datasets on various forums, it seems KPMG and Troy Hunt are just not aware of the fact that GDPR exists. https://en.wikipedia.org/wiki/General_Data_Protection_Regula... Its quite interesting putting in various peoples email addresses to see what sites they are linked to. Maybe once he has made some money out of it, a GDPR claim and financial settlement can be made a…

[deleted]

Re: Project Svalbard: The Future of Have I Been Pwned

#40
post #27

Earlier quoted context omitted.

And whilst its impossible to police effectively the datasets on various forums, it seems KPMG and Troy Hunt are just not aware of the fact that GDPR exists. https://en.wikipedia.org/wiki/General_Data_Protection_Regula... Its quite interesting putting in various peoples email addresses to see what sites they are linked to. Maybe once he has made some money out of it, a GDPR claim and financial settlement can be made a…

Does this really fall foul of GDPR? I would have guessed that once your data is in the wild, there is nothing in GDPR that applies. GDPR puts certain responsibilities on groups you give your data to treat that data in certain ways in terms of who it is shared with, which would not seem to apply to someone offering a lookup of an in the wild dataset. I'm curious if my naive understanding of this is wrong.

It’s a very easy fix, confirm ownership of the email address before exposing the results.
Post reply on HN