How is making money from stolen data legal? My email address is in the database and I never consented to it. Is there no legal repercussion?
Project Svalbard: The Future of Have I Been Pwned
131–140 of 160 posts
Re: Project Svalbard: The Future of Have I Been Pwned
#132Can we move the project into a blockchain and run it on IPFS? EDIT: Serious question, generate hashes out of the leaked logins, store them in a blockchain and provide an interface for lookup via IPFS. Those credentials are considered burned anyway so storing them for ever in a blockchain won't matter. Being in a blockchain anyone can access the data and use them for example on a registration page.
What value would a blockchain add here over a database?
Especially if privatized.
Blockchain is Very overrated, but it could be useful in keeping data "safe" where the temptation would exist to index or obscure results. Especially where data collection and censoring / disclosure has value to certain markets, i.e. Timed/rated or delayed disclosure, sic.
IDK, it's not impossible, but it's not my wheelhouse either.
I don't see any reuse or value to old databases and hashes being public, so it's missing that purpose to exist or be used/shared. Like a lot of blockchain is. It's not enough to exist, it has to be shared and kept alive. I suppose.
Still, If you look at the way AV and user security is handled, there are potential vectors to prevent or anticipate, especially if the process of disclosure is censored or segregated.
Perhaps also if they proactively lean towards purges or spontaneous negative actions, in order to obscure their intent or actual content / behavior.
HIBP relies on disclosure, and if it were woven into a typical service structure, there would be a temptation to "alleviate" the workload for customers, offering to "feed the beast" with positive results and competitive, defensive tactics against 3rd parties offering a similar product.
Which could segment the disclosure process, so that you would have multiple options, much the way that AV and Malware is handled.
And now you have the same failures as AV and Malware being segmented domains.
The probability of a corporation being incentivized to airbrush a 3rd party listing in a semi-corporate "index" or offering "alternatives" to anxious, very large corporations to disclosure or remediation. Especially if they deal with financial or legal data, or specific disclosure requirements.
And have problems with timely disclosure, or any disclosure.
Imagine if a clearing house for disclosure existed as a Symantec or Kaspersky "Subscription", with tiers of access and disclosure prevention for corporate members, wrapped up in a daily routine app, such as a 2FA/Password manager.
So that a disclosure would be made silently by the subscription service, without disclosing details, or the level of breach, etc. The accounts or corporations breached, would just have their entire client accounts auto-reset and the updated password would be applied to your password manager within a batch process without the user(s), the press, the security agencies, or the hacker(s) being notified.
That, instead of revealing the time period, the hashes of usernames & passwords, or the name of the user, or their IDs, it would just be rotated on a regular basis, and invisibly managed.
Its a concept with some value, ie "paranoid" security features as a service, to prevent or anticipate disaster, sic. But handled via a handshake type batch process of cycling password management.
But this also has potential for occlusion and obfuscation, especially in examples where the breach would be a crime, or need to be disclosed to federal/state/police agencies, etc.
Thankfully, most security policy would prevent this kind of amorphous takeover, but for small businesses and large businesses, having access security taken away and handled by 3rd parties, for convenience, is inevitable.
Re: Project Svalbard: The Future of Have I Been Pwned
#133But we see that so often. The original founder of a thing has a list of requirements he wants met, he wants to stay onboard. But then stuff happens and the buyer uses his control. Think Instagram, Whatsapp, Tumblr(?) - there are thousand examples. I'd hope Troy reconsidered the "just create a business yourself" solution. That could be structured in a way that makes sure the trust Troy earned stays linked to the proje…
I understand Troy, especially his fear of a burnout. That's no joke. I think there are several interesting companies, besides Mozilla. I could see F-Secure making an offer. HIBP ticks a lot of boxes when it comes to business security, password reuse beeing a big issue there. Mikko and his team have a proofen track record and are well connected in the grey-hat area. Plus, they are in Finnland, near to Norway :)
I'd be surprised if F-Secure made another acquisition so soon.
Re: Project Svalbard: The Future of Have I Been Pwned
#134So why was the owner of LeakedSource arrested and charged, and this guy isn't? He did the same thing. Only instead of selling to hackers, he sold our hacked data to companies and governments.
Re: Project Svalbard: The Future of Have I Been Pwned
#135Re: Project Svalbard: The Future of Have I Been Pwned
#136I came here hoping it was something about Svalbard. I went there a couple years ago in the dead of winter. It's an amazing place.
Re: Project Svalbard: The Future of Have I Been Pwned
#137But we see that so often. The original founder of a thing has a list of requirements he wants met, he wants to stay onboard. But then stuff happens and the buyer uses his control. Think Instagram, Whatsapp, Tumblr(?) - there are thousand examples. I'd hope Troy reconsidered the "just create a business yourself" solution. That could be structured in a way that makes sure the trust Troy earned stays linked to the proje…
For context, I've sold a business, been a full time entrepreneur for about 16 years, got it wrong many times and am currently the founder/CEO of a biz with a team of around 40 people, strong cashflow and we continue to grow and innovate - and we're founder controlled. I met with Troy briefly for coffee about 8 to 12 months ago and we chatted a bit about this. I sensed his aversion to growing the biz back then. Seemed…
Re: Project Svalbard: The Future of Have I Been Pwned
#138I came here hoping it was something about Svalbard. I went there a couple years ago in the dead of winter. It's an amazing place.
Tell us more! I'm planning for a longyearbien/svalbard trip towards the end of this year or summer next year.
I went in the dead of winter, so might be a little different from what you might experience in summer. https://www.facebook.com/dheera/media_set?set=a.101010917929...
Re: Project Svalbard: The Future of Have I Been Pwned
#139In some ways, wouldn't it be great if the internet had evolved with, analogously to DNS, 'User Name Servers', like a sort of global distributed IAM? Leak monitoring would be a service provided by the UNS, not falling to a volunteer, and credential revocation could be automatic and immediate. I suppose we sort of have that bolted on with OpenID/OAuth, but that's still 'choose a provider' rather than 'this is the one w…
Re: Project Svalbard: The Future of Have I Been Pwned
#140Can we move the project into a blockchain and run it on IPFS? EDIT: Serious question, generate hashes out of the leaked logins, store them in a blockchain and provide an interface for lookup via IPFS. Those credentials are considered burned anyway so storing them for ever in a blockchain won't matter. Being in a blockchain anyone can access the data and use them for example on a registration page.
What value would a blockchain add here over a database?