Live data from Hacker News

Authentication and the Have I Been Pwned API

troyhunt.com

71–80 of 125 posts

Re: Authentication and the Have I Been Pwned API

#71
post #52
post #21

Earlier quoted context omitted.

I don't see it as him monetizing the stolen data, but the mere existence of it.

No getting around that he sell access to stolen data. He didn't orginally steal it. He collected the illegal dumps and runs a service on top of that data. There is nothing wrong selling stolen data provided someone else dumped it first.

So fencing stolen goods is not illegal if someone else stole it? I don't think so. Stolen is stolen -- nobody has any right to sell it.

Re: Authentication and the Have I Been Pwned API

#72

> Late last year after seeing a similar pattern with a well-known hosting provider, I reached out to them to try and better understand what was going on. I provided a bunch of IP addresses which they promptly investigated and reported back to me on I'd love to know how to get a hosting provider to actually answer such requests. (I hope the answer isn't just "be high profile". I'm hoping the answer is more like "know…

How are you contacting them? If you use the correct abuse contact you'll usually get a response. We (IPinfo.io) are adding abuse contact info to our API within the next week or so (see https://twitter.com/ipinfoio/status/1138901541937602560 ) - let me know if you'd like early access.

Typically via abuse contacts or abuse forms.

The only type of service providers I've ever had useful responses from are email/mailing-list service providers, many of which will very quickly investigate and terminate spammers.

Re: Authentication and the Have I Been Pwned API

#73

Boom, now Troy is monetizing stolen data. Unethical and illegal.

He gives a cost breakdown showing that he's almost guaranteed to lose money off it. Azure is charging him 3.5$ per 1 million calls to ratelimit/charge people for using the api. He's charging 3.5$. Consider that Stripe will be taking another 35 cents or so... lets just say if this was a monetization method it's not a very good one.

He can try to justify it however he likes -- its selling stolen goods. Just because you sell stolen goods under their value, or under your costs to provide does not suddenly make it ok.

Re: Authentication and the Have I Been Pwned API

#74
post #15

Boom, now Troy is monetizing stolen data. Unethical and illegal.

It does cost money to run a service like this. He's historically had sponsors, but you can't expect someone to run a high traffic service for free forever.

And the local pawn shop has expenses too. Just because they have to pay rent and electricity costs does not make selling a stolen item legal.

Re: Authentication and the Have I Been Pwned API

#75
post #15

Earlier quoted context omitted.

It does cost money to run a service like this. He's historically had sponsors, but you can't expect someone to run a high traffic service for free forever.

And the local pawn shop has expenses too. Just because they have to pay rent and electricity costs does not make selling a stolen item legal.

There's a difference - he's not selling the leaked passwords. He's selling the information that a password has been leaked for a certain account. You can't buy stolen passwords from the site, so it's perfectly legal.

Re: Authentication and the Have I Been Pwned API

#76
post #75

Earlier quoted context omitted.

And the local pawn shop has expenses too. Just because they have to pay rent and electricity costs does not make selling a stolen item legal.

There's a difference - he's not selling the leaked passwords. He's selling the information that a password has been leaked for a certain account. You can't buy stolen passwords from the site, so it's perfectly legal.

I don't think it is that clear -- he is selling access to a data set containing PII (email address or account names). Its stolen data. One can make a case that free and open access to this data set is a common good, however once money is involved, one is conducting business with data that one did not legally obtain. It is not 'perfectly legal'.

Re: Authentication and the Have I Been Pwned API

#77
post #36

> One thing I want to be crystal clear about here is that the $3.50 fee is no way an attempt to monetise something I always wanted to provide for free. If this was true, then all revenue made from those 3.5 would get donated to a worthy cause, not donated into Troy's own pocket. I am not saying that he shouldn't monetise it, but please let's be honest about it. > The point is that the $3.50 number is pretty much bang…

This is such a clearly useful, legitimate service. You cannot tell the bad guys to delete your data. The next best thing is to be alerted when your data is found in a bad guy’s trove.

It's not that clear cut unfortunately.

What do you really know about Troy and his service? Really just what he wants you to know.

For example, Troy stores extremely valuable information about millions of people without their consent. A lesbian women in the Arabs, who might have had her credentials breached on a gay forum, who also has a gambling addiction and had her password breached on a gambling website and on another dating website for prostitution services might not want some Aussie guy selling all that information about her to anyone who pays him money. There is nothing, absolutely nothing ethical about this!

My sister does not know anything about Troy, I showed her his Twitter profile and the first things which stood out to her:

- Old man

- Orange skin like Trump

- Loves to show off outdated cars

- Making occasionally snarky comments about Indians, Indonesians and other Asian people, always suggesting that anything illegal is coming from those countries

- Constantly tries to self validate himself by bragging with something expensive he's recently bought in life

- Very capitalistic and money focused individual

It's not great optics for people who have never seen his blog. His blog is just marketing at the end of the day. There is no regulation, no actual organisation or anyone who can be held accountable for gross mishandling of the data.

It's just an old Aussie guy who stores hordes of stolen data on his private laptop and in his private cloud and sells it to other people who clearly gain benefit from collecting that data from his service.

There is trust and naivity, and in this case anyone who doesn't find it slightly dodgy is simply naive. Sorry, but that is the reality.

Re: Authentication and the Have I Been Pwned API

#78
post #64
post #63

Earlier quoted context omitted.

As discussed elsewhere in this thread, there are real benefits provided to bad guys by allowing them to look up this information about anybody in a central location.

This just feels like another iteration of the Full Disclosure debate.

I’ve never heard Full Disclosure concepts applied to serving stolen PII in an API.

The reason is that the purpose of full disclosure is to shame the vendor into ensuring the patch is made, and to warn the user base that the attack is possible, while disclosing a flaw in a commercial product.

In this case, we are not effectively doing either naming or shaming by publishing actual email addresses, rather than just user counts and the type of hashing that was performed.

And at the same time the information being “bartered” is private user information and not merely identifying a flaw in a commercial product.

I fail to see how an API into the HIBP database can be justified under the concept of full-disclosure. Particularly when the service could have been implemented as an email report to the queried email address.

Re: Authentication and the Have I Been Pwned API

#79

Earlier quoted context omitted.

See also elsethread about "not a token" — but, also: > There's a couple of these and they're largely due to me trying to make sure I get this feature out as early as possible and continue to run things on a shoestring cost wise Using the Authorization header can cause significant problems with both clients and servers, and also might unintentionally permit browsers to directly query the server if they can be convince…

I'm not sure how browsers using the API would be a concern. Someone paid for the key, so it should be up to them to use it how they please (within rate limits).

Allowing browsers to query directly would break the terms of engagement specified by the site operator, who specified that a proxy shall be used to concentrate end-user requests for a given paid key. That’s their right as service operator. I can construct plausible scenarios why this is a sensible choice, but the underlying point is that they clearly regardless made that choice after thinking it through.

Re: Authentication and the Have I Been Pwned API

#80

Earlier quoted context omitted.

That would only solve paying for services if you are an amoral service provider and don't care where the money really comes from as long as you get paid. It doesn't do anything for people who don't want their services used by bad actors, which is increasingly the case these days - see all the people concerned about privacy and how big tech companies use their data. It's not going to help for anything social where you…

>It doesn't do anything for people who don't want their services used by bad actors, which is increasingly the case these days My comment illustrates precisely how such an incentive structure denies high-resource demand users. >That would only solve paying for services if you are an amoral service provider and don't care where the money really comes from as long as you get paid. This makes no sense to me, sorry. Are…

By "amoral" I don't mean immoral, I mean you don't care what anyone does and you're happy not knowing the consequences of your actions.

Depending on what you're providing, maybe that's fine. In the open source world, we give away code all the time, to everyone. Most public reading material is fine.

But services differ and for some services of interest to bad actors, many people are concerned about the consequences when they do business.

Post reply on HN