Live data from Hacker News

Project Svalbard: The Future of Have I Been Pwned

troyhunt.com

151–160 of 160 posts

Re: Project Svalbard: The Future of Have I Been Pwned

#151
post #61

So why was the owner of LeakedSource arrested and charged, and this guy isn't? He did the same thing. Only instead of selling to hackers, he sold our hacked data to companies and governments.

I agree with your sentiment, but there is the difference in criminal intent with the former.

It's legal to sell armor piercing bullets, but marketing them as "cop killers" will not fly.

Re: Project Svalbard: The Future of Have I Been Pwned

#152

Earlier quoted context omitted.

I'm afraid I agree with basically nothing you've written here! I trust Troy Hunt more than I trust OP's examples of Facebook and Verizon. I also trust his competence more than I trust theirs. Whose to say that anybody won't make any of the mistakes you mention. FWIW I would doubt he would sell to either of these companies, but it's undeniable that you give up control when you sell and people have made incorrect judgm…

> FWIW I would doubt he would sell to either of these companies He might not, but 6 months later the company he sells to *might. Or if public could be taken over with little choice in the matter. As you say, control is gone once he sells.

But until that point, you might have a good enough product: One that has momentum and requires effort to corrupt, that users are aware of and have expectations about, and that presents value that people otherwise might not have known is possible. Control being lost doesn't necessitate that all the value & impact is lost with it.

Re: Project Svalbard: The Future of Have I Been Pwned

#153

Earlier quoted context omitted.

This isn't, by no means, a belittlement against Troy Hunt, but here are some things to consider: What makes Troy Hunt any more trustworthy? Do you think he can't make a mistake? What if his operation suddenly can't handle something because of X reason? What if he's breached himself or any of the services he's using break down or worse, provide invalid data or incorrect data? What if user Y searches his site, finds ou…

I'm afraid I agree with basically nothing you've written here! I trust Troy Hunt more than I trust OP's examples of Facebook and Verizon. I also trust his competence more than I trust theirs. Whose to say that anybody won't make any of the mistakes you mention. FWIW I would doubt he would sell to either of these companies, but it's undeniable that you give up control when you sell and people have made incorrect judgm…

Your argument is self contradictory because you seem to make an exclusion for Troy's fallibility by pointing to my same argument about the fallibility of others. There's no reason other than you think Troy is some super human.

Troy has basically said nothing about his manual verification process and he says its the worst part of the architecture. There seems to be no mechanism of removing your email from the list once it's added so he'll just keep adding/merging data I guess until it starts giving false positives. He doesn't have the infrastructure to make this scale into a reasonable utility. Even if he did hire employs, he's now delegating responsibility which will introduce new potential judgement holes into the process.

Simply put, it's too big for him. And it has nothing to do with trust. Venture capital is a crap excuse because now there's a profit motive for the service for something that should arguably be non-profit. Venture capital has a track record for producing several, high profile companies that make no profit for years and are compromised in themselves.

The best thing he could do is pass it to Mozilla or some other tech non-profit. It would be even better if it was a government service.

Remember, the founder of Facebook still runs the company. It got big, and look what happened.

Re: Project Svalbard: The Future of Have I Been Pwned

#154
post #35

But we see that so often. The original founder of a thing has a list of requirements he wants met, he wants to stay onboard. But then stuff happens and the buyer uses his control. Think Instagram, Whatsapp, Tumblr(?) - there are thousand examples. I'd hope Troy reconsidered the "just create a business yourself" solution. That could be structured in a way that makes sure the trust Troy earned stays linked to the proje…

For context, I've sold a business, been a full time entrepreneur for about 16 years, got it wrong many times and am currently the founder/CEO of a biz with a team of around 40 people, strong cashflow and we continue to grow and innovate - and we're founder controlled. I met with Troy briefly for coffee about 8 to 12 months ago and we chatted a bit about this. I sensed his aversion to growing the biz back then. Seemed…

HIBP shouldn't be for profit because it's harvesting personal data and it should be used as a mechanism for people to be aware of serious breaches. There's a lot of legal entanglement possible with this with HIPAA being an example of what can happen. It's probably a more difficult path, but in my opinion, HIBP should be a tax funded service because it's largely a public good product.

Re: Project Svalbard: The Future of Have I Been Pwned

#155

Earlier quoted context omitted.

I'm afraid I agree with basically nothing you've written here! I trust Troy Hunt more than I trust OP's examples of Facebook and Verizon. I also trust his competence more than I trust theirs. Whose to say that anybody won't make any of the mistakes you mention. FWIW I would doubt he would sell to either of these companies, but it's undeniable that you give up control when you sell and people have made incorrect judgm…

Your argument is self contradictory because you seem to make an exclusion for Troy's fallibility by pointing to my same argument about the fallibility of others. There's no reason other than you think Troy is some super human. Troy has basically said nothing about his manual verification process and he says its the worst part of the architecture. There seems to be no mechanism of removing your email from the list onc…

The argument was not self-contradictory. I did not say that Troy was infallible, I specifically said that anybody, not just Troy, could make the mistakes you listed. That was to demonstrate the fallacy in your argument that he should give up HIBP because he might make mistakes.

Contrary to what you say, Troy has detailed his verification process. There also is an opt out form on the site which will allow you remove your email from the current dumps and future ones.

Troy is talking about somebody acquiring HIBP. This implies he is not necessarily looking to give it away for free. There are already paid aspects of HIBP.

I would have no issue with it going to Mozilla.

I can't tell if you're joking by suggesting he give it to a government or by comparing him to Zuck.

I guess we're at least agreed on Mozilla, who he is already talking to.

Re: Project Svalbard: The Future of Have I Been Pwned

#157

Earlier quoted context omitted.

Your argument is self contradictory because you seem to make an exclusion for Troy's fallibility by pointing to my same argument about the fallibility of others. There's no reason other than you think Troy is some super human. Troy has basically said nothing about his manual verification process and he says its the worst part of the architecture. There seems to be no mechanism of removing your email from the list onc…

The argument was not self-contradictory. I did not say that Troy was infallible, I specifically said that anybody, not just Troy, could make the mistakes you listed. That was to demonstrate the fallacy in your argument that he should give up HIBP because he might make mistakes. Contrary to what you say, Troy has detailed his verification process. There also is an opt out form on the site which will allow you remove y…

I looked at his architecture diagram and his complaints about it. He specifically cites his manual verification process as being a problem and does not go into detail on how its done. How do we know dumpmon is legit? The file is a legitimate compromised file? Whether the file contains adequate data and is adequately scrubbed? Why isn't HIBP open source?

And what I was trying to argue is that we shouldn't put so much faith in one man. Whatever he does, it will, more than likely, not be feasible for him to control all himself. Especially with the legal ramifications of storing private data.

And I don't know why you think it's a joke to trust the government with something like this. We trust them with a lot more dangerous things. Considering it's the only entity that can compel a business to do something, it could actually work out if there was ever a law requiring breaches to be reported.

Re: Project Svalbard: The Future of Have I Been Pwned

#159
post #27
post #18

Earlier quoted context omitted.

Something to keep in mind is that the datasets being shared with Troy are almost all already available on underground forums, some openly, some for sale.

And whilst its impossible to police effectively the datasets on various forums, it seems KPMG and Troy Hunt are just not aware of the fact that GDPR exists. https://en.wikipedia.org/wiki/General_Data_Protection_Regula... Its quite interesting putting in various peoples email addresses to see what sites they are linked to. Maybe once he has made some money out of it, a GDPR claim and financial settlement can be made a…

[deleted]

Re: Project Svalbard: The Future of Have I Been Pwned

#160
post #95

Earlier quoted context omitted.

Yes, you're right, I'm sure that the guy who is at the forefront of campaigning about personal data protection, has been running this service for years, has advised governments on privacy breach regulation, and has contracts to help european governments monitor their domains for breaches, has no idea whatsoever about the most prominent personal data regulation regime in the world. Oh wait: https://www.troyhunt.com/fr…

Authorities now handling it, out of my hands. I dont want my details appearing on that website so anyone who knows me can put my email addresses (past and present) to see what hacked sites or databases its appeared on.

[deleted]
Post reply on HN