"After 4 and a bit years, by far and away the most popular method with an uptake of more than 90% is versioning via the URL. So that's all V3 supports. I don't care about the philosophical arguments to the contrary, I care about working software and in this case, the people have well and truly spoken. I don't want to have to maintain code and provide support for something people barely use when there's a perfectly vi…
Funny thing is here I am wondering why he didn't pass a query parameter instead of altering the path or adding a header to version the API... does anyone know? It has the advantage of being clickable while not implying the resource is different.
Authentication and the Have I Been Pwned API
91–100 of 125 posts
Re: Authentication and the Have I Been Pwned API
#92Earlier quoted context omitted.
He gives a cost breakdown showing that he's almost guaranteed to lose money off it. Azure is charging him 3.5$ per 1 million calls to ratelimit/charge people for using the api. He's charging 3.5$. Consider that Stripe will be taking another 35 cents or so... lets just say if this was a monetization method it's not a very good one.
He can try to justify it however he likes -- its selling stolen goods. Just because you sell stolen goods under their value, or under your costs to provide does not suddenly make it ok.
You are quite simply wrong and you should just admit it, rather than repeating your ludicrous claims in ever more hysterical terms.
Re: Authentication and the Have I Been Pwned API
#93All this seems to be hinting more than ever, that the time to provide these results directly and exclusively to the email address being queried is approaching. Why is this API being abused? Because it provides valuable information—which took a significant amount of effort to curate—about an email address. The list of services which have lost my (hashed or not) password at some point ever in the past eventually turns…
Sorry, but the cat is out of the bag. HIBP is evening the playing field, making the data less valuable to those who have the skills to collect it. It's the same thing as responsible/full disclosure; by making this information available to anyone (publish a vulnerability), you greatly reduce the power of those who have the skills to collect it anyway (the person who found the 0day). So yes, this information needs to b…
Are there additional benefits of the public api that on balance benefit the public more than attackers?
Re: Authentication and the Have I Been Pwned API
#94Earlier quoted context omitted.
> Should every OS which uses windows be able to call itself Windows, because windows are a quite old thing as well? > Like it or not, there is an rfc for this and using it for anything else would be code smell at best No but every OS that uses windows can call them windows....
I guess they should be able to call them windows. Can you link to any tool which uses bearer tokens and doesn't grant them through oauth2? Or it's internal, please explain how the token is obtained. I haven't seen any to date but I guess I could be wrong
Yes: https://www.pelion.com/docs/device-management/current/integr...
(I know I've seen and used many others, but Pelion comes first to mind because I used to work on it.)
Re: Authentication and the Have I Been Pwned API
#95I wish the post made more clear, ideally right at the top, that the new fee applies only to third-party apps that access the HIBP API, not to end users whose email addresses are being checked against the API. You have to read through the post a bit before that becomes clear. Individual users who just want to figure out whether they've been pwned will not have to pony up the cash. They can still visit https://haveibee…
It would also be great to emphasize that this only applies to the HIBP API, and the Pwned Passwords API will still be free. (It's mentioned about half-way through the article.)
Re: Authentication and the Have I Been Pwned API
#96All this seems to be hinting more than ever, that the time to provide these results directly and exclusively to the email address being queried is approaching. Why is this API being abused? Because it provides valuable information—which took a significant amount of effort to curate—about an email address. The list of services which have lost my (hashed or not) password at some point ever in the past eventually turns…
Just think of the number of clueless users who would mark such a notification as spam, and the number of old, dead addresses, some of which are now spamtraps.
edit: clarify bulk vs. individual notifications
Re: Authentication and the Have I Been Pwned API
#97Earlier quoted context omitted.
This is such a clearly useful, legitimate service. You cannot tell the bad guys to delete your data. The next best thing is to be alerted when your data is found in a bad guy’s trove.
It's not that clear cut unfortunately. What do you really know about Troy and his service? Really just what he wants you to know. For example, Troy stores extremely valuable information about millions of people without their consent. A lesbian women in the Arabs, who might have had her credentials breached on a gay forum, who also has a gambling addiction and had her password breached on a gambling website and on ano…
Re: Authentication and the Have I Been Pwned API
#98Earlier quoted context omitted.
Sorry, but the cat is out of the bag. HIBP is evening the playing field, making the data less valuable to those who have the skills to collect it. It's the same thing as responsible/full disclosure; by making this information available to anyone (publish a vulnerability), you greatly reduce the power of those who have the skills to collect it anyway (the person who found the 0day). So yes, this information needs to b…
"Disclosure" could mean many things. The idea of providing the info directly via email to the affected user seems to adequately disclose things to the relevant parties. Are there additional benefits of the public api that on balance benefit the public more than attackers?
Imagine it being $500/month to access HIBP, because that's the alternative, not some, "everyone agrees to only use this info for good".
Re: Authentication and the Have I Been Pwned API
#99All this seems to be hinting more than ever, that the time to provide these results directly and exclusively to the email address being queried is approaching. Why is this API being abused? Because it provides valuable information—which took a significant amount of effort to curate—about an email address. The list of services which have lost my (hashed or not) password at some point ever in the past eventually turns…
Bulk emailing notifications to all affected addresses would be a deliverability nightmare, and would require manual intervention at most ISPs to prevent these messages from being blocked, which said ISPs may or may not be willing to do. Just think of the number of clueless users who would mark such a notification as spam, and the number of old, dead addresses, some of which are now spamtraps. edit: clarify bulk vs. i…
Re: Authentication and the Have I Been Pwned API
#100Earlier quoted context omitted.
Bulk emailing notifications to all affected addresses would be a deliverability nightmare, and would require manual intervention at most ISPs to prevent these messages from being blocked, which said ISPs may or may not be willing to do. Just think of the number of clueless users who would mark such a notification as spam, and the number of old, dead addresses, some of which are now spamtraps. edit: clarify bulk vs. i…
That's a service Have I Been Pwned has been offering for years...?
But I realize the wording in the original post is a little ambiguous; I had read "provide ... directly" as implying "push", but that may not be the case, and if so my comment above is not relevant.