I hope that the SHA1 hashes remain freely available for download. I use them to build a bloom filter for password vetting. We should all do away with password complexity rules (except minimum length) and simply test a large, comprehensive exposed password bloom filter for membership. It's very fast (constant time) and efficient and if the test returns no, then it's safe for a user to select that password. Here's the…
Cool! I did something similar. First I used a bloom filter then a golomb set. https://github.com/terencechow/pwnedpasswords
Project Svalbard: The Future of Have I Been Pwned
81–90 of 160 posts
Re: Project Svalbard: The Future of Have I Been Pwned
#82Earlier quoted context omitted.
It’s a very easy fix, confirm ownership of the email address before exposing the results.
...if the password for said email address is already visible on the same page (assuming negligent password reuse) what kind of verification could you hope for?
Re: Project Svalbard: The Future of Have I Been Pwned
#83This is possibly a step by Troy to mitigate that risk, and given his position I’m surprised he didn’t mention that at all in this post.
Re: Project Svalbard: The Future of Have I Been Pwned
#84Earlier quoted context omitted.
Troy works with Microsoft currently, so I doubt it would work with Mozilla as MS have Edge
Microsoft Regional Director don't work for Microsoft. If that's what you are referring to. They are recognized by Microsoft based on one's expertise & skills.
Re: Project Svalbard: The Future of Have I Been Pwned
#85Earlier quoted context omitted.
Does this really fall foul of GDPR? I would have guessed that once your data is in the wild, there is nothing in GDPR that applies. GDPR puts certain responsibilities on groups you give your data to treat that data in certain ways in terms of who it is shared with, which would not seem to apply to someone offering a lookup of an in the wild dataset. I'm curious if my naive understanding of this is wrong.
It’s a very easy fix, confirm ownership of the email address before exposing the results.
Re: Project Svalbard: The Future of Have I Been Pwned
#86Re: Project Svalbard: The Future of Have I Been Pwned
#87So why was the owner of LeakedSource arrested and charged, and this guy isn't? He did the same thing. Only instead of selling to hackers, he sold our hacked data to companies and governments.
Re: Project Svalbard: The Future of Have I Been Pwned
#88I cannot say enough praises of Troy and HIBP. But it is a risky operation. I understand HIBP derives its value from grey-ish hats sharing with Troy any leaked dataset they find because they know him or because of his reputation. If he leaves, it is not clear to me that his trust and reputation will stay behind with the company running HIBP. The minute HIBP ceases to be the central place for these new datasets to be s…
Something to keep in mind is that the datasets being shared with Troy are almost all already available on underground forums, some openly, some for sale.
Re: Project Svalbard: The Future of Have I Been Pwned
#89Earlier quoted context omitted.
Something to keep in mind is that the datasets being shared with Troy are almost all already available on underground forums, some openly, some for sale.
And whilst its impossible to police effectively the datasets on various forums, it seems KPMG and Troy Hunt are just not aware of the fact that GDPR exists. https://en.wikipedia.org/wiki/General_Data_Protection_Regula... Its quite interesting putting in various peoples email addresses to see what sites they are linked to. Maybe once he has made some money out of it, a GDPR claim and financial settlement can be made a…
Oh wait: https://www.troyhunt.com/free-course-the-gdpr-attack-plan/ https://www.troyhunt.com/new-pluralsight-course-the-state-of... https://twitter.com/troyhunt/status/1017679101698572295