Live data from Hacker News

Project Svalbard, Have I Been Pwned and its ongoing independence

troyhunt.com

61–70 of 100 posts

Re: Project Svalbard, Have I Been Pwned and its ongoing independence

#61
He should really have built a password validating/auditing software for commercial use.

I used hibp in a corporate setting, like most others I looked to see if there was a way to check AD and Linux for bad passwords, a few people had some open sourcey things that only work retroactively with manual execution. We evaluated the need and decided on pursuing an unrelated commercial product that does all the password auditing using known bad passwords among a long list of other things. Since the start I wondered why HIBP did not do this. Having existing enterprise customers would have given him a lot more leverage.

Re: Project Svalbard, Have I Been Pwned and its ongoing independence

#62
The Best hotel booking system Theme and plugin in WordPress

You might be searching a WP plugin of hotels, otherwise, you are thinking to make a hotel booking system, with any of the highest-paid WordPress booking plugins, you’ll save yourself tons of your time and work, if you read this article. Plus, be very eco-friendly, avoiding all the paper stuff. Now got to browse the online anymore if you’d wish to introduce your very own booking or appointment system on your website.

Notice: for brand spanking, new business owners and professional individuals, do yourself a favor and appearance into WordPress business themes with integrated booking forms. In short, they provide you an all-in-one solution for your ultimate online appearance.

By offering to book straight from your website, clients can quickly check once you or your services are available. They will schedule the proper date without the necessity of calling you beforehand. Let’s face it, giving a call isn’t that trendy anymore. Plus, it’s going to take longer compared to picking and clicking on the proper dates and hitting the Book Now button. We beat a rush lately.

https://www.electronthemes.com/best-hotel-booking-system-plu...

Re: Project Svalbard, Have I Been Pwned and its ongoing independence

#63

Sorry, but the more I read this, the more I feel like KPMG is the main reason for the failed process... > And so in September, we granted exclusivity to a bidder. (...) And so began the extensive due diligence. KPMG had warned me about this phase right at the beginning of the process and from memory, the word they used was something akin to "onerous". You're supposed to have your ducks in a row before you launch the…

Also true. When in banking we generally ran 2 parties in parallel through final documentation.

By the way the game theory and signaling is intense!

Re: Project Svalbard, Have I Been Pwned and its ongoing independence

#64

The Best hotel booking system Theme and plugin in WordPress You might be searching a WP plugin of hotels, otherwise, you are thinking to make a hotel booking system, with any of the highest-paid WordPress booking plugins, you’ll save yourself tons of your time and work, if you read this article. Plus, be very eco-friendly, avoiding all the paper stuff. Now got to browse the online anymore if you’d wish to introduce y…

@dang

Re: Project Svalbard, Have I Been Pwned and its ongoing independence

#65

The Best hotel booking system Theme and plugin in WordPress You might be searching a WP plugin of hotels, otherwise, you are thinking to make a hotel booking system, with any of the highest-paid WordPress booking plugins, you’ll save yourself tons of your time and work, if you read this article. Plus, be very eco-friendly, avoiding all the paper stuff. Now got to browse the online anymore if you’d wish to introduce y…

On a meta note I'm honestly surprised that somebody took the time to script a bot to create accounts and post obvious spam on HN. It's like, the least plausible place on the planet to find customers by spamming...

I believe this is the first I've ever seen such a spam comment created by a spam-specific new account.

Re: Project Svalbard, Have I Been Pwned and its ongoing independence

#66
post #16

I'm surprised the author contacted KMPG to run M&A for a small independently run website..? Not sure what I'm missing here.

I'm surprised anyone would contact KPMG for M&A at all, in that they're primarily an accountant / auditor, not an M&A shop.

Over a third (39%) of KPMG's revenue comes from management consulting services. KPMG has an entire arm of the company that is classified as "Advisory" (aka consulting), of which M&A is a big part of, and it is completely separated from the accounting/audit arms.

All of the Big 4 "accounting firms" actually also house the largest consulting companies in the world, but somehow their old reputation of being "primarily an accountant / auditor" keeps sticking.

Re: Project Svalbard, Have I Been Pwned and its ongoing independence

#67

Sorry but, how is Have I Been Pwned anything but a text search of data that is already publicly available? Normally a company is valuable because of some kind of value add. Either they generate data nobody else can, or they do something with that data nobody else can. HIBP does neither of those things. It literally searches one column of a database, and tells you if there was a match. You could run HIBP using a total…

From the article: "Anyone can cobble together a website with some APIs and load in a ton of data breaches, but establishing trust is a whole different story. Trust in the way I run the service is an absolutely pivotal part of HIBP and it's something I built organically rather than setting out to earn it, now here I was with big companies putting a value on it."

Yeah, so it's nothing but branding. There is nothing about this site that requires trust, since the data is already available. HIBP got popular on Twitter / the internet and is now a well known name in cyber.

Re: Project Svalbard, Have I Been Pwned and its ongoing independence

#68
post #59

Sorry, but the more I read this, the more I feel like KPMG is the main reason for the failed process... > And so in September, we granted exclusivity to a bidder. (...) And so began the extensive due diligence. KPMG had warned me about this phase right at the beginning of the process and from memory, the word they used was something akin to "onerous". You're supposed to have your ducks in a row before you launch the…

I'm curious if Mr. Hunt has ever been through either side of a diligence process. Everything in his list sounds like what you need to check the audit and compliance boxes at any "real" company. I've been through a dozen audits from prospective _customers_ that are worse than his description, even apart from our internal audits, so if someone was going to buy a company I'd expect essentially a superset of BS from all…

Agreed. I really feel for Hunt because the process surely is exhausting for anyone, let alone a sole business owner. But I have to wonder what he expected when he started to go down this path. It sounds like KPMG may not have adequately prepared him for this, or (based on my experience with consultants similar to KPMG) they probably assumed that he knew what he was getting himself into (he apparently did not).

That said, I don't put all of the blame on KPMG. It takes only a few minutes searching on the internet or speaking with advisors to learn that shopping for a buyout is a long, extremely hard process. In particular, I couldn't help but audibly laugh at Hunt's seeming incredulity at the request for "Documentation of the Company's technical operations". Hunt is trying to sell a tech company whose primary business value comes from the technical infrastructure, operations, and data. I don't want to sound too blunt, but...no fucking shit the buyers are going to want to know about his technical processes and infrastructure. Did he seriously think someone would even think about buying HIBP without investigating exactly what technical stack and data they are buying? Even for companies where the value isn't as based in the tech processes, nobody wants to buy a pile of steaming spaghetti code.

It should be common sense that this is the type of information that buyers would ask for. This list of tech processes and documentation of infrastructure is something that should have been put together first thing before Hunt even started shopping around.

Re: Project Svalbard, Have I Been Pwned and its ongoing independence

#69

Anyone have a clue who the potential acquirer was? Just curious as to whether they wanted the brand of Troy Hunt as the databases are public and most technically savvy organizations can put one together.

My guess is Symantec due to their change of corporate direction/vision in 2019 (selling enterprise sec biz to Broadcom, concentrating on consumer/smallbiz cybersecurity). see https://www.pcmag.com/news/symantec-sells-off-name-enterpris...

Would line up well with Troy Hunt's mention of "It was a change in business model that not only made the deal infeasible from their perspective, but also from mine; some of the most important criteria for the possible suitor were simply no longer there"

But then I saw the date for the pcmag article above (Aug 2019) and I'm not sure now. Seems Symantec's divestiture is too early for this broken deal. Or would it take several months after the sale? I found an article from 2019 Nov 4 about Broadcom closing the Symantec purchase - https://www.crn.com/news/security/done-deal-10-7-billion-bro...

Re: Project Svalbard, Have I Been Pwned and its ongoing independence

#70

Earlier quoted context omitted.

From the article: "Anyone can cobble together a website with some APIs and load in a ton of data breaches, but establishing trust is a whole different story. Trust in the way I run the service is an absolutely pivotal part of HIBP and it's something I built organically rather than setting out to earn it, now here I was with big companies putting a value on it."

Yeah, so it's nothing but branding. There is nothing about this site that requires trust, since the data is already available. HIBP got popular on Twitter / the internet and is now a well known name in cyber.

Well, to be pedantic, it's not just a simple SQL query, it's also a percolation query server and notification system.

It's like saying that Pingdom is nothing more than a cron job.

Post reply on HN