Live data from Hacker News

Project Svalbard: The Future of Have I Been Pwned

troyhunt.com

131–140 of 160 posts

Re: Project Svalbard: The Future of Have I Been Pwned

#131

How is making money from stolen data legal? My email address is in the database and I never consented to it. Is there no legal repercussion?

Ya it sucks. I had a client whose data was stolen and uploaded to his site. He wouldn't reply to me... He works for Microsoft and his operation mostly benefits the big companies - and can really damage a small company that happened to start out with bad software.

Re: Project Svalbard: The Future of Have I Been Pwned

#132
post #75

Can we move the project into a blockchain and run it on IPFS? EDIT: Serious question, generate hashes out of the leaked logins, store them in a blockchain and provide an interface for lookup via IPFS. Those credentials are considered burned anyway so storing them for ever in a blockchain won't matter. Being in a blockchain anyone can access the data and use them for example on a registration page.

What value would a blockchain add here over a database?

A breach-monitoring service could act as a data washing service, sic.

Especially if privatized.

Blockchain is Very overrated, but it could be useful in keeping data "safe" where the temptation would exist to index or obscure results. Especially where data collection and censoring / disclosure has value to certain markets, i.e. Timed/rated or delayed disclosure, sic.

IDK, it's not impossible, but it's not my wheelhouse either.

I don't see any reuse or value to old databases and hashes being public, so it's missing that purpose to exist or be used/shared. Like a lot of blockchain is. It's not enough to exist, it has to be shared and kept alive. I suppose.

Still, If you look at the way AV and user security is handled, there are potential vectors to prevent or anticipate, especially if the process of disclosure is censored or segregated.

Perhaps also if they proactively lean towards purges or spontaneous negative actions, in order to obscure their intent or actual content / behavior.

HIBP relies on disclosure, and if it were woven into a typical service structure, there would be a temptation to "alleviate" the workload for customers, offering to "feed the beast" with positive results and competitive, defensive tactics against 3rd parties offering a similar product.

Which could segment the disclosure process, so that you would have multiple options, much the way that AV and Malware is handled.

And now you have the same failures as AV and Malware being segmented domains.

The probability of a corporation being incentivized to airbrush a 3rd party listing in a semi-corporate "index" or offering "alternatives" to anxious, very large corporations to disclosure or remediation. Especially if they deal with financial or legal data, or specific disclosure requirements.

And have problems with timely disclosure, or any disclosure.

Imagine if a clearing house for disclosure existed as a Symantec or Kaspersky "Subscription", with tiers of access and disclosure prevention for corporate members, wrapped up in a daily routine app, such as a 2FA/Password manager.

So that a disclosure would be made silently by the subscription service, without disclosing details, or the level of breach, etc. The accounts or corporations breached, would just have their entire client accounts auto-reset and the updated password would be applied to your password manager within a batch process without the user(s), the press, the security agencies, or the hacker(s) being notified.

That, instead of revealing the time period, the hashes of usernames & passwords, or the name of the user, or their IDs, it would just be rotated on a regular basis, and invisibly managed.

Its a concept with some value, ie "paranoid" security features as a service, to prevent or anticipate disaster, sic. But handled via a handshake type batch process of cycling password management.

But this also has potential for occlusion and obfuscation, especially in examples where the breach would be a crime, or need to be disclosed to federal/state/police agencies, etc.

Thankfully, most security policy would prevent this kind of amorphous takeover, but for small businesses and large businesses, having access security taken away and handled by 3rd parties, for convenience, is inevitable.

Re: Project Svalbard: The Future of Have I Been Pwned

#133
post #68
post #35

But we see that so often. The original founder of a thing has a list of requirements he wants met, he wants to stay onboard. But then stuff happens and the buyer uses his control. Think Instagram, Whatsapp, Tumblr(?) - there are thousand examples. I'd hope Troy reconsidered the "just create a business yourself" solution. That could be structured in a way that makes sure the trust Troy earned stays linked to the proje…

I understand Troy, especially his fear of a burnout. That's no joke. I think there are several interesting companies, besides Mozilla. I could see F-Secure making an offer. HIBP ticks a lot of boxes when it comes to business security, password reuse beeing a big issue there. Mikko and his team have a proofen track record and are well connected in the grey-hat area. Plus, they are in Finnland, near to Norway :)

>I could see F-Secure making an offer

I'd be surprised if F-Secure made another acquisition so soon.

Re: Project Svalbard: The Future of Have I Been Pwned

#134
post #61

So why was the owner of LeakedSource arrested and charged, and this guy isn't? He did the same thing. Only instead of selling to hackers, he sold our hacked data to companies and governments.

Yep. I have a client that is working on arresting someone who uploaded all of their customer data to this guy's website. None of them will answer - it seems like they only care about money and their operation just benefits the big companies. Most small businesses don't have the resources to completely security proof their custom services against these $3K+ hacking tools that the script kiddies use (who steal data and upload it to Troy's services).

Re: Project Svalbard: The Future of Have I Been Pwned

#137
post #35

But we see that so often. The original founder of a thing has a list of requirements he wants met, he wants to stay onboard. But then stuff happens and the buyer uses his control. Think Instagram, Whatsapp, Tumblr(?) - there are thousand examples. I'd hope Troy reconsidered the "just create a business yourself" solution. That could be structured in a way that makes sure the trust Troy earned stays linked to the proje…

For context, I've sold a business, been a full time entrepreneur for about 16 years, got it wrong many times and am currently the founder/CEO of a biz with a team of around 40 people, strong cashflow and we continue to grow and innovate - and we're founder controlled. I met with Troy briefly for coffee about 8 to 12 months ago and we chatted a bit about this. I sensed his aversion to growing the biz back then. Seemed…

Fantastic post. This is exactly how it goes, especially with a bootstrapped company. Detachment and delegation are everything.

Re: Project Svalbard: The Future of Have I Been Pwned

#138
post #136
post #135

I came here hoping it was something about Svalbard. I went there a couple years ago in the dead of winter. It's an amazing place.

Tell us more! I'm planning for a longyearbien/svalbard trip towards the end of this year or summer next year.

Sure, what do you want to know?

I went in the dead of winter, so might be a little different from what you might experience in summer. https://www.facebook.com/dheera/media_set?set=a.101010917929...

Re: Project Svalbard: The Future of Have I Been Pwned

#139
post #114

In some ways, wouldn't it be great if the internet had evolved with, analogously to DNS, 'User Name Servers', like a sort of global distributed IAM? Leak monitoring would be a service provided by the UNS, not falling to a volunteer, and credential revocation could be automatic and immediate. I suppose we sort of have that bolted on with OpenID/OAuth, but that's still 'choose a provider' rather than 'this is the one w…

There is a recent RFC which applies the DNS to security checks for passwords, credit cards, etc. https://tools.ietf.org/html/rfc8567

Re: Project Svalbard: The Future of Have I Been Pwned

#140
post #75

Can we move the project into a blockchain and run it on IPFS? EDIT: Serious question, generate hashes out of the leaked logins, store them in a blockchain and provide an interface for lookup via IPFS. Those credentials are considered burned anyway so storing them for ever in a blockchain won't matter. Being in a blockchain anyone can access the data and use them for example on a registration page.

What value would a blockchain add here over a database?

[deleted]
Post reply on HN