Live data from Hacker News

Project Svalbard: The Future of Have I Been Pwned

troyhunt.com

61–70 of 160 posts

Re: Project Svalbard: The Future of Have I Been Pwned

#62
post #54
post #53

He's still a Microsoft employee is he not? Wonder if he couldn't just bring it in-house?

When has he ever worked for Microsoft? https://www.linkedin.com/in/troyhunt/ https://www.troyhunt.com/microsoft-regional-director/ - "I’m not going to work for Microsoft and despite the title of “Microsoft Regional Director”, I’m no more an employee than what I was (and still am) an MVP"

Ahh, the title has always thrown me off.

Re: Project Svalbard: The Future of Have I Been Pwned

#63
post #41

Earlier quoted context omitted.

I’m not sure how GDPR applies to HIBP. GDPR is all about data that is shared by the user. But HIBP is about data that hasn’t been shared by a user, but rather, is available publicly. It’s a grey area at the very least.

> GDPR is all about data that is shared by the user. No it isn't. It covers my data no matter how you got it, with a few exceptions. EDIT: Please feel free to point to the legislation showing that GDPR only applies to data supplied by the subject.

You're not wrong, but purely from a practical standpoint, your data is out there and without a service like this to hold these companies to account, they could cover things up/downplay the situation/be too incompetent to know they've leaked data.

An operation like this levels the playing field and lets us collectively hold companies to their responsibilities.

Re: Project Svalbard: The Future of Have I Been Pwned

#64
post #41

Earlier quoted context omitted.

I’m not sure how GDPR applies to HIBP. GDPR is all about data that is shared by the user. But HIBP is about data that hasn’t been shared by a user, but rather, is available publicly. It’s a grey area at the very least.

> GDPR is all about data that is shared by the user. No it isn't. It covers my data no matter how you got it, with a few exceptions. EDIT: Please feel free to point to the legislation showing that GDPR only applies to data supplied by the subject.

https://en.wikipedia.org/wiki/General_Data_Protection_Regula...

"The regulation applies if the data controller (an organisation that collects data from EU residents), or processor (an organisation that processes data on behalf of a data controller like cloud service providers), or the data subject (person) is based in the EU. Under certain circumstances,[2] the regulation also applies to organisations based outside the EU if they collect or process personal data of individuals located inside the EU. The regulation does not apply to the processing of data by a person for a "purely personal or household activity and thus with no connection to a professional or commercial activity." (Recital 18) "

The EU laws apply to people and entities outside of the EU, he is not immune from these EU laws because he is affecting the lives of every European who has an email address in this website.

Re: Project Svalbard: The Future of Have I Been Pwned

#65

HIBP could be an excellent B2B offering for companies. Imagine someone like Microsoft offering it as an addon to their business clients to improve security practices. Or a more independent company offering it as a standalone service, kinda like Mozilla (Monitor) or even something like Symantec (tho they seem to be bleeding money recently)

1Password's Watchtower feature uses it, I'd pay a few bucks extra for the functionality if required.

Re: Project Svalbard: The Future of Have I Been Pwned

#66

Earlier quoted context omitted.

Does this really fall foul of GDPR? I would have guessed that once your data is in the wild, there is nothing in GDPR that applies. GDPR puts certain responsibilities on groups you give your data to treat that data in certain ways in terms of who it is shared with, which would not seem to apply to someone offering a lookup of an in the wild dataset. I'm curious if my naive understanding of this is wrong.

I’m not sure how GDPR applies to HIBP. GDPR is all about data that is shared by the user. But HIBP is about data that hasn’t been shared by a user, but rather, is available publicly. It’s a grey area at the very least.

>GDPR is all about data that is shared by the user.

Wrong, wrong, wrong.

GDPR covers the processing of any data about an identified or identifiable individual.

Re: Project Svalbard: The Future of Have I Been Pwned

#67
post #31
post #27

Earlier quoted context omitted.

And whilst its impossible to police effectively the datasets on various forums, it seems KPMG and Troy Hunt are just not aware of the fact that GDPR exists. https://en.wikipedia.org/wiki/General_Data_Protection_Regula... Its quite interesting putting in various peoples email addresses to see what sites they are linked to. Maybe once he has made some money out of it, a GDPR claim and financial settlement can be made a…

> Maybe once he has made some money out of it, a GDPR claim and financial settlement Do you think GDPR fines go to the person, and not the regulator?

People can sue (Article 79) and claim compensation for actual damages suffered (Article 82) due to a violation of the GDPR.

Administrative fines levied by a supervisory authority generally don't go to people who have had their personal data processed illegally, though.

Re: Project Svalbard: The Future of Have I Been Pwned

#68
post #35

But we see that so often. The original founder of a thing has a list of requirements he wants met, he wants to stay onboard. But then stuff happens and the buyer uses his control. Think Instagram, Whatsapp, Tumblr(?) - there are thousand examples. I'd hope Troy reconsidered the "just create a business yourself" solution. That could be structured in a way that makes sure the trust Troy earned stays linked to the proje…

I understand Troy, especially his fear of a burnout. That's no joke. I think there are several interesting companies, besides Mozilla. I could see F-Secure making an offer. HIBP ticks a lot of boxes when it comes to business security, password reuse beeing a big issue there. Mikko and his team have a proofen track record and are well connected in the grey-hat area. Plus, they are in Finnland, near to Norway :)
Post reply on HN