Live data from Hacker News

Project Svalbard: The Future of Have I Been Pwned

troyhunt.com

111–120 of 160 posts

Re: Project Svalbard: The Future of Have I Been Pwned

#111
I understand why Troy is doing this. Security is a big and a complex endeavor and having majority of the stuff done by himself alone is taking a toll.

One option that Troy could have done is to spin up a team / small company that would continue this project - with full control and guidance under his direction. That way, the trust that he has built from everyone at the community will be carried forward as the project progresses and matures further.

This will also allow visibility and transparency knowing that the people who would be working on this project will have access to him and everyone is on board on the direction moving forward.

Lots of companies / venture capitalists would be willing to support this cause which could provide the financing the project will need to be sustained and grow further.

Re: Project Svalbard: The Future of Have I Been Pwned

#114
In some ways, wouldn't it be great if the internet had evolved with, analogously to DNS, 'User Name Servers', like a sort of global distributed IAM?

Leak monitoring would be a service provided by the UNS, not falling to a volunteer, and credential revocation could be automatic and immediate.

I suppose we sort of have that bolted on with OpenID/OAuth, but that's still 'choose a provider' rather than 'this is the one way', with many servers run by different entities, but one 'system'.

Re: Project Svalbard: The Future of Have I Been Pwned

#115
post #55
post #53

He's still a Microsoft employee is he not? Wonder if he couldn't just bring it in-house?

He was not a Microsoft employee. He is a MVP but worked for Pfizer iirc. Now he is with Pluralsight.

> Now he is with Pluralsight

You sure? As far I know, he's an independent now.

Re: Project Svalbard: The Future of Have I Been Pwned

#116
post #114

In some ways, wouldn't it be great if the internet had evolved with, analogously to DNS, 'User Name Servers', like a sort of global distributed IAM? Leak monitoring would be a service provided by the UNS, not falling to a volunteer, and credential revocation could be automatic and immediate. I suppose we sort of have that bolted on with OpenID/OAuth, but that's still 'choose a provider' rather than 'this is the one w…

[deleted]

Re: Project Svalbard: The Future of Have I Been Pwned

#117
post #114

In some ways, wouldn't it be great if the internet had evolved with, analogously to DNS, 'User Name Servers', like a sort of global distributed IAM? Leak monitoring would be a service provided by the UNS, not falling to a volunteer, and credential revocation could be automatic and immediate. I suppose we sort of have that bolted on with OpenID/OAuth, but that's still 'choose a provider' rather than 'this is the one w…

It's existed since 1988: LDAP/X.500[1] It's just not used globally because of three reasons, as far as I can tell,

1) most people don't want their information public and searchable to that extent

2) most orgs _want_ to silo you in or otherwise control your account

3) the org using x500 still needs to have their own permissions separate from the central directory, which is the harder part of auth[nz], so just rolling your own authn is often easier.

[1] https://en.wikipedia.org/wiki/X.500

Re: Project Svalbard: The Future of Have I Been Pwned

#118
post #98

Earlier quoted context omitted.

HIBP only works because of trust in Troy Hunt, few organisations have that. Maybe an organisation not involved in advertising at any level.

Could they leverage some sort of Troy partnership / oversight? "Troy Approved!" Mozilla is a good group, they've had missteps but I find them trustworthy and the combination would be pretty trustworthy IMO.

A Mozilla acquisition of HIBP could look alot like Mozilla buying HIBP from them, and then bringing Troy on board for a period of time as an evangelist, and the nature of being an open source, community focused org means that Troy could retain his ties to Mozilla as long as he wants to, as a staff member or volunteer.

I don't know how much has changed since I left Mozilla, but there were, and probably still are, a number of former employees and volunteer contributors that had a great degree of influence and input on various projects.

Heck, Troy might even be a good potential addition to the Mozilla board of directors at some point in the future.

Re: Project Svalbard: The Future of Have I Been Pwned

#119
post #35

But we see that so often. The original founder of a thing has a list of requirements he wants met, he wants to stay onboard. But then stuff happens and the buyer uses his control. Think Instagram, Whatsapp, Tumblr(?) - there are thousand examples. I'd hope Troy reconsidered the "just create a business yourself" solution. That could be structured in a way that makes sure the trust Troy earned stays linked to the proje…

This isn't, by no means, a belittlement against Troy Hunt, but here are some things to consider: What makes Troy Hunt any more trustworthy? Do you think he can't make a mistake? What if his operation suddenly can't handle something because of X reason? What if he's breached himself or any of the services he's using break down or worse, provide invalid data or incorrect data? What if user Y searches his site, finds ou…

I'm afraid I agree with basically nothing you've written here!

I trust Troy Hunt more than I trust OP's examples of Facebook and Verizon. I also trust his competence more than I trust theirs. Whose to say that anybody won't make any of the mistakes you mention. FWIW I would doubt he would sell to either of these companies, but it's undeniable that you give up control when you sell and people have made incorrect judgments before.

Nobody is suggesting he continue alone, rather that, if he feels that they're the only two options, he take some venture capital instead of selling the business.

The main reason not to do this is the one that he's given: it may not be the best thing for him personally, and the venture capital plan may be particularly negative for him. I think this reasoning has a lot of merit.

Re: Project Svalbard: The Future of Have I Been Pwned

#120

So many people saying the value of HIBP is the trust in Troy Hunt. But surely I'm not the only one that has used the service for years (and shared it with friends) without knowing anything about Troy Hunt...

Social credit and trust has a way of naturally propagating. Trust, beliefs, even world views are more often "caught" than deliberately and carefully chosen -- to the detriment of many. All it takes is a few liars with the appearance of trustworthiness to spread false beliefs very widely.

Note, my comment is not about Troy. Security-wise, I think the trust he carries is well-deserved.

Post reply on HN