Sign up

Troy Hunt

Not verified No WebSub updates Supports Webmention Not yet validated

Hi, I'm Troy Hunt, I write this blog, run "Have I Been Pwned" and am a Microsoft Regional Director and MVP who travels the world speaking at events and training technology professionals

Generator
Ghost 6.64
Public lists
davewiner/hackerNewsStars
Fetched

Troy Hunt Supports Webmention
Text • Troy Hunt

Weekly Update 521: Breach Perception v. Reality

Weekly Update 521: Breach Perception v. Reality

I think what really resonates with me this week is being able to completely turn the tables on perceptions around things like AI being the big bad hacking tool the news would have you believe. There's the stat I talk about where it's had literally 0%

Troy Hunt Supports Webmention
Text • Troy Hunt

Weekly Update 520: The Unscripted Edition

Weekly Update 520: The Unscripted Edition

I've started playing around with YouTube's "create video thumbnail", which hopefully will give me back a bit of time in my day (it used to be a manual job in Photoshop) and be a bit more interesting. And on that note, the imagery it&

Troy Hunt Supports Webmention
Text • Troy Hunt

Weekly Update 519: Breaches & Data Integrity

Weekly Update 519: Breaches & Data Integrity

It does feel like I've bitten off too much and am now chewing like crazy this week. The 3D printing talk with Elle in Oslo, the "normal" NDC infosec talk, the cyber-broken talk with Scott in Copenhagen and then those ratbag hackers keep dumping more

Troy Hunt Supports Webmention
Text • Troy Hunt

A Cautionary Tale About Data Breach Claims, Verification and Carhartt

A Cautionary Tale About Data Breach Claims, Verification and Carhartt

You're not going to believe this, but turns out you can't always take criminals at their word. Actually, I'll walk that back a bit as it may not even be the cybercrime guys who got this wrong, but it all starts here:

🚨Cyber

Troy Hunt Supports Webmention
Text • Troy Hunt

Weekly Update 518: IoT Doorlock Nirvana with UniFi

Weekly Update 518: IoT Doorlock Nirvana with UniFi

I genuinely think I've nailed the IoT door lock situation! Well, Ubiquiti has, but I think I've worked out how to put it all into a residential house and have it make sense. There are a few basic tenets:

  1. Main power (never have to rely on

Troy Hunt Supports Webmention
Text • Troy Hunt

Welcoming the Sri Lankan Government to Have I Been Pwned

Today, we welcome the 48th government onboarded to Have I Been Pwned’s free gov service: Sri Lanka. Sri Lanka CERT now has access to monitor Sri Lankan government domains against the data in HIBP, helping identify exposed government accounts and respond when they appear in new data breaches.

Troy Hunt Supports Webmention
Text • Troy Hunt

Weekly Update 517: Cyber Ransoms

Weekly Update 517: Cyber Ransoms

The current ransomware situation is a bit of a kludge (deep breath): a lot of ransomware (which often doesn't even involve "ware", it's just extortion) is carried out by kids who successfully make a truckload of money but can't spend it without

Troy Hunt Supports Webmention
Text • Troy Hunt

Weekly Update 516: Live From Vietnam

Weekly Update 516: Live From Vietnam

A little wind noise, a little connectivity flakiness, and a little lip-sync issues from YouTube, but look at that view! 🤩 Back to business, it's the Brinks Home FAQ I found most interesting this week. I mean, how do you write your own FAQ then fail to

Troy Hunt Supports Webmention
Text • Troy Hunt

Welcoming the Nepalese Government to Have I Been Pwned

Welcoming the Nepalese Government to Have I Been Pwned

Today, we welcome the 47th government onboarded to Have I Been Pwned’s free gov service: Nepal. Their National Cyber Security Centre now has access to monitor Nepalese government domains against the data in HIBP. This gives the NCSC the ability to identify exposure across government email addresses and

Troy Hunt Supports Webmention
Text • Troy Hunt

Weekly Update 515

Weekly Update 515

Apparently, Aussies are so obsessed with coffee that it's referred to as the coffee capital of the world down here (some bits, at least). "But what about Italy?" people ask. Having spent a lot of time in a lot of Italy, no, it's just

Troy Hunt Supports Webmention
Text • Troy Hunt

Weekly Update 514: This Week in Data Breaches

Weekly Update 514: This Week in Data Breaches

The Origin Energy breach down here in Aus is all over the news this week, and as with many breaches, it's multi-faceted. You've got them leading with "don't worry, your credit card is fine", the hacker leading with "they didn&

Troy Hunt Supports Webmention
Text • Troy Hunt

Weekly Update 513: Clauding The Home Network

Weekly Update 513: Clauding The Home Network

I reckon this week's video on how Claude is tying together info from UniFi, Home Assistant and the Pi-Hole is an absolute ripper. Or at least the concept is - if ever there was an actual value proposition for AI it's taking lots of noise and

Troy Hunt Supports Webmention
Text • Troy Hunt

Weekly Update 512: IoT Lockout Fail

Weekly Update 512: IoT Lockout Fail

"Build a smart home", they said. "It'll make life so much better", they said. Well, life wasn't very bloody good at 23:00 the other night after travelling 33 hours from Paris only to find the IoT doorlock batteries dead and the

Troy Hunt Supports Webmention
Text • Troy Hunt

Weekly Update 511: Live from my Riad in Marrakech

Weekly Update 511: Live from my Riad in Marrakech

How's this for a location?! I mean, last week was nice with Scott in Mallorca, but Marrakech is, well, wow 😮 Anyway, about those data breaches... This week I'm talking about the futility of attempting to remove piss from a pool, yet here we are, with

Troy Hunt Supports Webmention
Text • Troy Hunt

Swimming Pools, Pee, and Trying to Delete Your Data From the Internet

Swimming Pools, Pee, and Trying to Delete Your Data From the Internet

I can't recall if someone else originally came up with this saying or if I said it in some off-the-cuff comment and it just propagated, but since it's often attributed back to me, I'll relay it here regardless:

Trying to delete yourself

Troy Hunt Supports Webmention
Text • Troy Hunt

Weekly Update 510: Live From Mallorca with Scott Helme

Weekly Update 510: Live From Mallorca with Scott Helme

How's the view?! Back to business, it's now 8 years ago that Scott and I thought it would be a cool idea to build Why no HTTPS? We used the site to shame companies for not implementing their transport later security property, and to make it

Troy Hunt Supports Webmention
Text • Troy Hunt

Weekly Update 509

Weekly Update 509

I know enough about home cinema audiovisual to know there's a lot I don't know. It's conscious incompetence, if you like, which is different to the unconscious incompetence most people have on the topic. That's not to sound derogatory (it's

Troy Hunt Supports Webmention
Text • Troy Hunt

Weekly Update 508

Weekly Update 508

Light switches. How on earth is it so hard to find decent light switches?! It sounds ridiculous until you actually spend enough time looking for ones that meet two simple criteria:

  1. Aren't stateful (switch is up or down, has to be push-button)
  2. Looks good

Now, I'

Troy Hunt Supports Webmention
Text • Troy Hunt

Weekly Update 507

Weekly Update 507

1,000 breaches is one hell of a milestone. It's not just the process of getting data, verifying it, loading it, sending notifications etc, it's all the other stuff that goes into keeping the whole thing afloat. Legal docs. Trademarks. Accounting. Agreements. The most mind-numbingly boring

Troy Hunt Supports Webmention
Text • Troy Hunt

Welcoming the Philippine Government to Have I Been Pwned

Welcoming the Philippine Government to Have I Been Pwned

Today, we welcome the 46th government onboarded to Have I Been Pwned’s free gov service: the Philippines.

The Philippines’ National CERT, working with the Department of Information and Communications Technology, now has access to monitor official government domains against the data in HIBP. This gives their Cyber

Troy Hunt Supports Webmention
Text • Troy Hunt

1,000 Data Breaches Later, the Disclosure Lag is Worse Than Ever

1,000 Data Breaches Later, the Disclosure Lag is Worse Than Ever

Today, I loaded the 1,000th data breach into Have I Been Pwned. Reflecting on that milestone number, I pondered how to mark the occasion in writing, and what immediately came to mind was a very simple question: why is it still needed? Especially considering the emergence of privacy regulations

Troy Hunt Supports Webmention
Text • Troy Hunt

Weekly Update 506

Weekly Update 506

I'm finding it quite fascinating to watch the current spate of ShinyHunters breaches and dumps. There's the obvious criminality of it all, but then there's also the response from organisations (or lack thereof, as it relates to disclosure to victims), the appearance and disappearance

Troy Hunt Supports Webmention
Text • Troy Hunt

Welcoming the Bhutanese Government to Have I Been Pwned

Welcoming the Bhutanese Government to Have I Been Pwned

Today, we welcome the 45th government onboarded to Have I Been Pwned’s free gov service: Bhutan. The Bhutan Computer Incident Response Team, BtCIRT, now has access to monitor Bhutanese government domains against the data in HIBP. As Bhutan’s national CIRT, BtCIRT is responsible for consuming threat

Troy Hunt Supports Webmention
Text • Troy Hunt

Weekly Update 505

Weekly Update 505

Well, that didn't last long! Recording this on Saturday morning my time, I observed ShinyHunters having gone quiet since the massive haul that would have been the Instructure ransom. It was two weeks almost to the hour since I'd first heard rumour of payment being made,

Troy Hunt Supports Webmention
Text • Troy Hunt

Weekly Update 504

Weekly Update 504

It's a hot topic, the old "pay or don't pay" for hackers not to leak your data. Since recording this a few days ago, we've had Grafana go with the "no pay" approach, and I've seen a raft

Troy Hunt Supports Webmention
Text • Troy Hunt

Welcoming the Bahamian Government to Have I Been Pwned

Welcoming the Bahamian Government to Have I Been Pwned

Today, we welcome the 44th government onboarded to Have I Been Pwned’s free gov service: The Bahamas. The National Computer Incident Response Team of The Bahamas, CIRT-BS, now has access to monitor government domains against the data in HIBP. As the national CIRT, CIRT-BS is responsible for coordinating

Troy Hunt Supports Webmention
Text • Troy Hunt

Welcoming the Bangladesh Government to Have I Been Pwned

Today, we welcome the 43rd government onboarded to Have I Been Pwned's free gov service, Bangladesh. The BGD e-GOV CIRT department now has full access to query all their government domains via API, and monitor them against future breaches.

Bangladesh joins a growing list of national governments using

Troy Hunt Supports Webmention
Text • Troy Hunt

Welcoming the Costa Rican Government to Have I Been Pwned

Today, we welcome the 42nd government onboarded to Have I Been Pwned’s free gov service: Costa Rica.

The CSIRT of the Government of Costa Rica now has access to monitor government domains against the data in HIBP. This enables their national cybersecurity incident response team to identify exposure

Troy Hunt Supports Webmention
Text • Troy Hunt

Weekly Update 503

Weekly Update 503

Well, it's the day before the Instructure "pay or leak" deadline (at least by my Aussie watch), and the company remains removed from the ShinyHunters website. In its place sits a press statement that amounts to "we're not making any statements". So

Troy Hunt Supports Webmention
Text • Troy Hunt

Weekly Update 502

Weekly Update 502

It's a fascinating display of leverage: the ShinyHunters folks, with very limited resources and experience (their demographic will be teenagers to their early 20s), consistently gaining access to the data of massive brands. Not through technical ingenuity alone (although I'm sure there's a portion