Remove tag pwned-passwords
article thumbnail

The UK and Australian Governments Are Now Monitoring Their Gov Domains on Have I Been Pwned

Troy Hunt

If I'm honest, I'm constantly surprised by the extent of how far Have I Been Pwned (HIBP) is reaching these days. I'm very happy that HIBP is now a resource the UK and Aus governments can draw on to help their people help all of us live happier (and hopefully less pwned!) online lives.

article thumbnail

A Decade of Have I Been Pwned

Troy Hunt

"Have I been pwned?" Search for your account across multiple breaches [link] — Have I Been Pwned (@haveibeenpwned) December 4, 2013 And then, as they say, things kinda escalated quickly. You know why it's called "Have I Been Pwned"? Saying "pwned"! American Congress.

Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

Understanding Have I Been Pwned's Use of SHA-1 and k-Anonymity

Troy Hunt

Four and a half years ago now, I rolled out version 2 of HIBP's Pwned Passwords that implemented a really cool k-anonymity model courtesy of the brains at Cloudflare. Actually, the multiple problems, the first of which is that it's just way too fast for storing user passwords in an online system.

Passwords 122
article thumbnail

Analysing the (Alleged) Minneapolis Police Department "Hack"

Troy Hunt

I've now seen several versions of the same set of email addresses and passwords albeit with different attribution up the top of the file. Of the 689 unique email addresses, 654 of them are already in Have I Been Pwned. They're simple passwords most likely cracked from other breaches. Not convinced?

Passwords 145
article thumbnail

The Legitimisation of Have I Been Pwned

Troy Hunt

There's no way to sugar-coat this: Have I Been Pwned (HIBP) only exists due to a whole bunch of highly illegal activity that has harmed many individuals and organisations alike. But it's not just organisations that have already been pwned that are giving HIBP a shout-out, let me share some more proactive examples.

article thumbnail

I'm Open Sourcing the Have I Been Pwned Code Base

Troy Hunt

Let me just cut straight to it: I'm going to open source the Have I Been Pwned code base. link] — Junade Ali (@IcyApril) August 5, 2020 This tweet isn't entirely accurate; it was all Junade's idea and he designed the k-anonymity implementation for HIBP's Pwned Passwords. Let me explain why and how.

Passwords 145
article thumbnail

Have I Been Pwned Domain Searches: The Big 5 Announcements!

Troy Hunt

There are presently 201k people monitoring domains in Have I Been Pwned (HIBP). We can't add a meta tag. Read more: [link] — Have I Been Pwned (@haveibeenpwned) January 5, 2023 That's a sizeable whack of data, in fact it was the 14th largest in HIBP out of the existing 644 in there at the time.

IT 92