Live data from Hacker News

Project Svalbard, Have I Been Pwned and its ongoing independence

troyhunt.com

91–100 of 100 posts

Re: Project Svalbard, Have I Been Pwned and its ongoing independence

#91
post #82

Earlier quoted context omitted.

> There is also an unreasonable dependency on CloudFlare kool-aid for HIBP and his other services. How it is unreasonable? Do you criticize the hosting platform / cdn of every service you use? CF has been a huge help to Troy with optimizing caching and helping him with the k-anonymity setup to make the scale of HIBP possible with less infrastructure. Their network is top notch (sub 10ms for most population centers) a…

If your whole raison d'etre is to be a trusted source on privacy and security matters, then putting yourself in a position where you can't speak objectively about the organisation that controls 10% of the internet's traffic is massively compromising that. I'm sure Hunt will do his best, but how could anyone possibly make a fair judgement of something controversial like "Flexible SSL" when his livelihood is dependent…

I am sure that literally any one of our competitors would give Troy their service for free. He's free to leave whenever he wants. And he's 100% free to criticize us while remaining a customer.

Re: Project Svalbard, Have I Been Pwned and its ongoing independence

#92

Sorry but, how is Have I Been Pwned anything but a text search of data that is already publicly available? Normally a company is valuable because of some kind of value add. Either they generate data nobody else can, or they do something with that data nobody else can. HIBP does neither of those things. It literally searches one column of a database, and tells you if there was a match. You could run HIBP using a total…

I reckon HIBP adds at least (far more, tbh) as much value over 'text search of data that is already available' ad Dropbox does over 'FTP dump'.

Re: Project Svalbard, Have I Been Pwned and its ongoing independence

#93
It's interesting what HIBP reveals about both attackers and defenders.

HIBP held a long randomly generated password I used exclusively on tvtropes. It was in plaintext in a pw dump, suggesting they weren't even hashing at the time.

I contacted tvtropes a few times but got ignored with no announcement.

It's not a banking site, not sure what we should expect. But given compelling evidence of a breach and making no announcement to users seems irresponsible.

Re: Project Svalbard, Have I Been Pwned and its ongoing independence

#94
post #82

Earlier quoted context omitted.

If your whole raison d'etre is to be a trusted source on privacy and security matters, then putting yourself in a position where you can't speak objectively about the organisation that controls 10% of the internet's traffic is massively compromising that. I'm sure Hunt will do his best, but how could anyone possibly make a fair judgement of something controversial like "Flexible SSL" when his livelihood is dependent…

I am sure that literally any one of our competitors would give Troy their service for free. He's free to leave whenever he wants. And he's 100% free to criticize us while remaining a customer.

I love that you're here ... and as transparent as possible. Thanks for the work you do in keeping the Internet running (and as far as possible - "safe".

Re: Project Svalbard, Have I Been Pwned and its ongoing independence

#95

Anyone have a clue who the potential acquirer was? Just curious as to whether they wanted the brand of Troy Hunt as the databases are public and most technically savvy organizations can put one together.

Well Sophos was just taken private, so maybe them? I'm not sure how widely known these things are before they come out.

Re: Project Svalbard, Have I Been Pwned and its ongoing independence

#96

This whole things seems extremely naive and almost like a different Troy Hunt... Why KPMG? Their competence is below average for an above average price hiding behind a big corporate name. Why answer thousands of questions, the majority could have just been a copy paste one liner. You're selling a side gig, not a massive company. Also why selling it in the first place and then not wanting to give up control by limitin…

Troy is not primarily motivated by money anymore; he has plenty [1]. What's most important to him is that HIBP is run the way he wants it run, but with more resources than a single person can offer. He's willing to pay the "biggest bill in his life" in order to preserve that vision, which honestly just increases his reputation as a person you can trust. He can make those kinds of decisions because money is not the main issue.

[1] https://www.troyhunt.com/10-personal-finance-lessons-for-tec...

Re: Project Svalbard, Have I Been Pwned and its ongoing independence

#97
post #94

Earlier quoted context omitted.

I am sure that literally any one of our competitors would give Troy their service for free. He's free to leave whenever he wants. And he's 100% free to criticize us while remaining a customer.

I love that you're here ... and as transparent as possible. Thanks for the work you do in keeping the Internet running (and as far as possible - "safe".

Well, I've been here close to 13 years (https://news.ycombinator.com/user?id=jgrahamc). Seems a shame to leave now.

Re: Project Svalbard, Have I Been Pwned and its ongoing independence

#98
post #38
post #15

I think that's good that he doesn't sell, having built a enormous marketing presence and gained market trust is only a minor step away from actually monetizing that. Selling what he has right now does indeed come with golden handcuffs (sucks), but also any purchase price would come in vastly under the projects' potential. He could easily leverage this marketing presence to build a security SaaS company, create a huge…

> He could easily leverage this marketing presence to build a security SaaS company, create a huge conference, launch a big consultancy,... If it would be so easy it would've been done already.

He doesn't have the plan and associated funding and the people in place.

Maybe easy is the wrong word, but he's definitely well-positioned to reap more reward of what he achieved so far

Re: Project Svalbard, Have I Been Pwned and its ongoing independence

#99

Earlier quoted context omitted.

"good signal is inbound" - mhm yep definitely english

Hah sorry super busy, sorry. Inbound interest is a good initial signal that there's genuine interest on the other end. It's way better than reaching out. Somewhere between inbound & outbound is maintained relationships you push on. From having legit inbound interest, you still need to find an executive champion on the acquirer's side who'll spend months pushing through the lawyers, politics, etc, and ideally, has don…

I was commenting on the incredible level of jargon. This post is even more impressive!

Re: Project Svalbard, Have I Been Pwned and its ongoing independence

#100
post #60

Earlier quoted context omitted.

It’s a database with public data. Let’s not get carried away.

> I kid you not, was in a meeting at [big tech company] HQ in [HQ location] and a comment was made to the effect that "there is only one service they trust as a white hat (Troy and HIBP) and I'm like "fuck how does one guy corner the market on trust?" That's invaluable

Right up until someone needs to put a price on it.
Post reply on HN