Remove tag fundamental-rights
article thumbnail

Bypassing Browser Security Warnings with Pseudo Password Fields

Troy Hunt

For example, imagine you genuinely wanted to run a device requiring mains power in the centre of your inflatable pool - you're flat out of luck, right? Not everyone was happy about this because hey, HTTPS is hard, right? Plus, of course, the onclick event on the input box itself sets the placeholder text to an empty string.

article thumbnail

The Legitimisation of Have I Been Pwned

Troy Hunt

Transparency has been a huge part of that effort and I've always written and spoken candidly about my thought processes, how I handle data and very often, the mechanics of how I've built the service (have a scroll through the HIBP tag on this blog for many examples of each). ONLY check active passwords via the #DOWNLOADED list!