Live data from Hacker News

Project Svalbard: The Future of Have I Been Pwned

troyhunt.com

91–100 of 160 posts

Re: Project Svalbard: The Future of Have I Been Pwned

#91

Many people here assuming that Troy Hunt will leave HIBP after selling it. He explicitly mentions that he will remain a part of it: > I'll remain a part of HIBP. I fully intend to be part of the acquisition, that is some company gets me along with the project. HIBP's brand is intrinsically tied to mine and at present, it needs me to go along with it.

I understand his intent. This just isn't my first rodeo. It's not uncommon for there to be talk of grand intentions to stay on and lead after acquisition. It rarely works out that way.

Re: Project Svalbard: The Future of Have I Been Pwned

#92
post #61

So why was the owner of LeakedSource arrested and charged, and this guy isn't? He did the same thing. Only instead of selling to hackers, he sold our hacked data to companies and governments.

Does HIBP sell the raw data?

Nope. Though I suppose if HIBP itself were acquired, that would presumably include the raw data?

Re: Project Svalbard: The Future of Have I Been Pwned

#93
post #68
post #35

But we see that so often. The original founder of a thing has a list of requirements he wants met, he wants to stay onboard. But then stuff happens and the buyer uses his control. Think Instagram, Whatsapp, Tumblr(?) - there are thousand examples. I'd hope Troy reconsidered the "just create a business yourself" solution. That could be structured in a way that makes sure the trust Troy earned stays linked to the proje…

I understand Troy, especially his fear of a burnout. That's no joke. I think there are several interesting companies, besides Mozilla. I could see F-Secure making an offer. HIBP ticks a lot of boxes when it comes to business security, password reuse beeing a big issue there. Mikko and his team have a proofen track record and are well connected in the grey-hat area. Plus, they are in Finnland, near to Norway :)

If F-Secure is in Finnland, doesn't that mean they would have to delete user data on demand, undermining the service in doing so?

Re: Project Svalbard: The Future of Have I Been Pwned

#95
post #27

Earlier quoted context omitted.

And whilst its impossible to police effectively the datasets on various forums, it seems KPMG and Troy Hunt are just not aware of the fact that GDPR exists. https://en.wikipedia.org/wiki/General_Data_Protection_Regula... Its quite interesting putting in various peoples email addresses to see what sites they are linked to. Maybe once he has made some money out of it, a GDPR claim and financial settlement can be made a…

Yes, you're right, I'm sure that the guy who is at the forefront of campaigning about personal data protection, has been running this service for years, has advised governments on privacy breach regulation, and has contracts to help european governments monitor their domains for breaches, has no idea whatsoever about the most prominent personal data regulation regime in the world. Oh wait: https://www.troyhunt.com/fr…

Authorities now handling it, out of my hands. I dont want my details appearing on that website so anyone who knows me can put my email addresses (past and present) to see what hacked sites or databases its appeared on.

Re: Project Svalbard: The Future of Have I Been Pwned

#96
post #95

Earlier quoted context omitted.

Yes, you're right, I'm sure that the guy who is at the forefront of campaigning about personal data protection, has been running this service for years, has advised governments on privacy breach regulation, and has contracts to help european governments monitor their domains for breaches, has no idea whatsoever about the most prominent personal data regulation regime in the world. Oh wait: https://www.troyhunt.com/fr…

Authorities now handling it, out of my hands. I dont want my details appearing on that website so anyone who knows me can put my email addresses (past and present) to see what hacked sites or databases its appeared on.

That's the whole point. You can see the data that criminals are using and seeing. Don't blame the guy telling you about it.

Re: Project Svalbard: The Future of Have I Been Pwned

#97

Worth mentioning that the value of HIBP is largely based on trust in Troy Hunt. I think he’s an incredible guy who does incredible work; but he’s also an Australian citizen. Due to our new surveillance laws, he could be forced to backdoor HIBP, or more likely, Pwned Passwords. This is possibly a step by Troy to mitigate that risk, and given his position I’m surprised he didn’t mention that at all in this post.

I think Troy probably has more than enough social credit to simply ask for help on Twitter and receive pro-bono legal representation if regulators somehow embarked on a misguided attempt to target him or HIBP.

Re: Project Svalbard: The Future of Have I Been Pwned

#98
post #5

I'd love to see a non-profit organisation like Mozilla pick this up, but that's obviously going to mean a lot less money going to Troy. OTOH, it's kind of difficult to begrudge Troy gaining financially from HIBP, since he's spent years building it up and has helped increase security awareness for so many people.

HIBP only works because of trust in Troy Hunt, few organisations have that. Maybe an organisation not involved in advertising at any level.

Could they leverage some sort of Troy partnership / oversight?

"Troy Approved!"

Mozilla is a good group, they've had missteps but I find them trustworthy and the combination would be pretty trustworthy IMO.

Re: Project Svalbard: The Future of Have I Been Pwned

#99
post #93
post #68

Earlier quoted context omitted.

I understand Troy, especially his fear of a burnout. That's no joke. I think there are several interesting companies, besides Mozilla. I could see F-Secure making an offer. HIBP ticks a lot of boxes when it comes to business security, password reuse beeing a big issue there. Mikko and his team have a proofen track record and are well connected in the grey-hat area. Plus, they are in Finnland, near to Norway :)

If F-Secure is in Finnland, doesn't that mean they would have to delete user data on demand, undermining the service in doing so?

I wonder if you just have passwords and don't link them to usernames, then that wouldn't be "your data" because it can't be connected back to you?

Re: Project Svalbard: The Future of Have I Been Pwned

#100
post #93
post #68

Earlier quoted context omitted.

I understand Troy, especially his fear of a burnout. That's no joke. I think there are several interesting companies, besides Mozilla. I could see F-Secure making an offer. HIBP ticks a lot of boxes when it comes to business security, password reuse beeing a big issue there. Mikko and his team have a proofen track record and are well connected in the grey-hat area. Plus, they are in Finnland, near to Norway :)

If F-Secure is in Finnland, doesn't that mean they would have to delete user data on demand, undermining the service in doing so?

Undermine the service for who? The person who asked to have their data removed or the company who is interested in data about a specific person. If the answer is the latter then I think its fair that the person can ask to have their information removed. I think that Troy understands this distinction too and I also hope that HIBP remains that way.
Post reply on HN