Live data from Hacker News

Project Svalbard, Have I Been Pwned and its ongoing independence

troyhunt.com

71–80 of 100 posts

Re: Project Svalbard, Have I Been Pwned and its ongoing independence

#71

Sorry but, how is Have I Been Pwned anything but a text search of data that is already publicly available? Normally a company is valuable because of some kind of value add. Either they generate data nobody else can, or they do something with that data nobody else can. HIBP does neither of those things. It literally searches one column of a database, and tells you if there was a match. You could run HIBP using a total…

> Sorry but, how is Have I Been Pwned anything but a text search of data that is already publicly available?

To be fair, google is also a (very glorified) text search of publicly available data when you get right down to it. Value is a combination of how useful you are to other people and how popular you are with other people, not how technically complicated you are. HIBP is both useful and popular - hence its valuable.

Re: Project Svalbard, Have I Been Pwned and its ongoing independence

#72

Earlier quoted context omitted.

From the article: "Anyone can cobble together a website with some APIs and load in a ton of data breaches, but establishing trust is a whole different story. Trust in the way I run the service is an absolutely pivotal part of HIBP and it's something I built organically rather than setting out to earn it, now here I was with big companies putting a value on it."

Yeah, so it's nothing but branding. There is nothing about this site that requires trust, since the data is already available. HIBP got popular on Twitter / the internet and is now a well known name in cyber.

The reason that trust is important could be to do with verifying breaches.

In some of his articles discussing various breaches, he mentions reaching out to selected (potential) victims to verify some of the details.

Doing that does require a fair amount of trust by various victims of the people asking to verify.

If I was randomly contacted to verify some details in a breach, I'd be skeptical it was a phishing scheme.

If I was randomly contacted by Troy Hunt / HIBP - then I'd look at it much more seriously.

Re: Project Svalbard, Have I Been Pwned and its ongoing independence

#73
post #31

I appreciate what HIBP does, but I believe it serves Troy's personal brand more than it would any corporate owner. The biggest issue is the data is super stale. Things regularly pop up in SpyCloud 6-12 months before HIBP, and as a result they are a much more attractive acquisition target. There is also an unreasonable dependency on CloudFlare kool-aid for HIBP and his other services. I reached out to Troy about spons…

> I was effectively offering to cover all the companies infrastructure costs

So basically what CF does today? Except he would have reengineer everything to fit a new setup? Was he snarky or just explaining himself?

Re: Project Svalbard, Have I Been Pwned and its ongoing independence

#74
post #61

He should really have built a password validating/auditing software for commercial use. I used hibp in a corporate setting, like most others I looked to see if there was a way to check AD and Linux for bad passwords, a few people had some open sourcey things that only work retroactively with manual execution. We evaluated the need and decided on pursuing an unrelated commercial product that does all the password audi…

That's basically what we've done with https://safepass.me/ and https://pwncheck.me/ ... and HIBP is the dataset we ship to our customers by default. If you are still looking to validate passwords when they're set, give me a nudge :)

We don't advertise the linux/PAM support since we have failed to find a market for it (usually things end up being hooked up onto AD one way or the other)...

Re: Project Svalbard, Have I Been Pwned and its ongoing independence

#75
post #16

I'm surprised the author contacted KMPG to run M&A for a small independently run website..? Not sure what I'm missing here.

I'm surprised anyone would contact KPMG for M&A at all, in that they're primarily an accountant / auditor, not an M&A shop.

According to the post which introduced the project be was already using them and they referred him internally

Back in April during a regular catchup with the folks at KPMG about some otherwise mundane financial stuff (I've met with advisers regularly as my own financial state became more complex), they suggested I have a chat with their Mergers and Acquisition (M&A) practice about finding a new home for HIBP. I was comfy doing that; we have a long relationship and they understand not just HIBP, but the broader spectrum of the cyber things I do day to day.

https://www.troyhunt.com/project-svalbard-the-future-of-have...

Re: Project Svalbard, Have I Been Pwned and its ongoing independence

#76
post #60

Earlier quoted context omitted.

It’s a database with public data. Let’s not get carried away.

> I kid you not, was in a meeting at [big tech company] HQ in [HQ location] and a comment was made to the effect that "there is only one service they trust as a white hat (Troy and HIBP) and I'm like "fuck how does one guy corner the market on trust?" That's invaluable

But also, much of that value is potentially lost the moment the sale goes through.

Re: Project Svalbard, Have I Been Pwned and its ongoing independence

#77
post #31

I appreciate what HIBP does, but I believe it serves Troy's personal brand more than it would any corporate owner. The biggest issue is the data is super stale. Things regularly pop up in SpyCloud 6-12 months before HIBP, and as a result they are a much more attractive acquisition target. There is also an unreasonable dependency on CloudFlare kool-aid for HIBP and his other services. I reached out to Troy about spons…

HIBP's M&A process & Troy's hurdles in running HIBP highlights two fundamental points of friction in running a single person company.

Reg. Value of a single person company.

>This was another really unexpected part of the experience - how people perceived me personally and put a value on my brand.

May be Troy really didn't expect that only person running an entity to be bought would be valued, sometimes even higher than the product/service itself; but it also needs to be understood that the company which is willing to buy an entity for a single person is undertaking an extraordinarily huge risk due to the Bus factor.

Reg. Compliances of a Business when running as a single person.

>I still manually verified every breach, hand edited every logo of a pwned company, issued (and chased) every invoice, did the tax returns and prepared the business activity statements.

At-least Troy seems to be located in a jurisdiction with straight forward business regulations. May be, most of the compliances could be automated.

There are countries out there where companies, even if run by a single person needs to comply with literally hundreds of regulations, with a new one popping up each month all to benefit the corrupt bureaucracy i.e. If you want to comply every regulation there, you still need to bribe. But the system and people who help with such regulations(auditing, lawyers) favour those who don't comply just because of larger bribes! So, even if you automate every other part of our business, you cannot automate out of corrupt bureaucracy.

M&A is one of the fundamental hurdles in a single person company, although there are other advantages such as freedom, cost-benefit etc.[1]

[1]https://hitstartup.com/being-single-founder-vs-having-co-fou...

Re: Project Svalbard, Have I Been Pwned and its ongoing independence

#78
post #41

Earlier quoted context omitted.

I emailed Troy to ask if he'd consider operating it as a non-profit utility similar to Let's Encrypt, and offered to help (because it's only fair if you come with an ask).

I've been sitting here wondering why bringing HIBP into an existing non-profit foundation wasn't the desired outcome. Having HIBP under the control of corporate interests seems icky.

Do we know for sure it wasn't? Couldn't Mr Hunt have wanted Mozilla to take over, but they weren't keen .. what other non-profit options fit here? Apache?

Re: Project Svalbard, Have I Been Pwned and its ongoing independence

#79
post #46

My confidence level on this is very low, because what do I know, but my emotional commitment to this take, having been a small business operator (in Hunt's field) for a couple decades now, is very high: This makes me very sad. Not that the deal fell through, because of course it did, but because of the process he undertook. Every part of it makes me sad. Any correction or rebuttal I get to this will make me happier,…

> Can we think of a company with this slide in their deck and that valuation?

WeWork?

Re: Project Svalbard, Have I Been Pwned and its ongoing independence

#80

Damn that sounds like an incredibly exhausting experience, and all he got out of it was... a hugely expensive bill. All I can say is props to him to keeping his principles, I really hope he's be able to grow HIBP into a sustainable gig for himself and a small core team.

Sounds like he also got a bit of clarity of what he really wants.
Post reply on HN