Operation Endgame

Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite

Today we loaded 16.5M email addresses and 13.5M unique passwords provided by law enforcement agencies into Have I Been Pwned (HIBP) following botnet takedowns in a campaign they’ve coined Operation Endgame. That link provides an excellent overview so start there then come back to this blog

Continue reading Operation Endgame

Weekly Update 401

Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite

Ah, episode 401, the unauthorised one! Ok, that was terrible, but what’s not terrible is finally getting some serious dev resources behind HIBP. I touch on it in the blog post but imagine all the different stuff I have to spread myself across to run this thing, and

Continue reading Weekly Update 401

Have I Been Pwned Employee 1.0: Stefán Jökull Sigurðarson

Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite

We often do that in this industry, the whole “1.0” thing, but it seems apt here. I started Have I Been Pwned (HIBP) in 2013 as a pet project that scratched an itch, so I never really thought of myself as an “employee”. Over time,

Continue reading Have I Been Pwned Employee 1.0: Stefán Jökull Sigurðarson

Weekly Update 400

Presently sponsored by: Kolide is an endpoint security solution for teams that want to meet SOC2 compliance goals without sacrificing privacy. Learn more here.

This is the 400th time I’ve sat down in front of the camera and done one of these videos. Every single week since the 23rd of September in 2016 regardless of location, health, stress and all sorts of other crazy things that have gone on in my life

Continue reading Weekly Update 400

Weekly Update 399

Presently sponsored by: Kolide believes that maintaining endpoint security shouldn’t mean compromising employee privacy. Check out our manifesto: Honest Security.

The Post Millennial breach in this week’s video is an interesting one, most notably because of the presence of the mailing lists. Now, as I’ve said in every piece of communication I’ve put out on this incident, the lists are what whoever defaced the

Continue reading Weekly Update 399

Weekly Update 398

Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite

How many different angles can you have on one data breach? Facial recognition (which probably isn’t actual biometrics), gambling, offshore developers, unpaid bills, extortion, sloppy password practices and now, an arrest. On pondering it more after today’s livestream, it’s the unfathomable stupidity of publishing

Continue reading Weekly Update 398

Weekly Update 397

Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite

Banks. They screw us on interest rates, they screw us on fees and they screw us on passwords. Remember the old “bank grade security” adage? I took this saying to task almost a decade ago now but it seems that at least as far as password advice goes,

Continue reading Weekly Update 397

Weekly Update 396

Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite

“More Data Breaches Than You Can Shake a Stick At”. That seems like a reasonable summary and I suggest there are two main reasons for this observation. Firstly, there are simply loads of breaches happening and you know this already because, well, you read my stuff! Secondly, There

Continue reading Weekly Update 396

Weekly Update 395

Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite

Data breach verification: that seems like a good place to start given the discussion in this week’s video about Accor. Watch the vid for the whole thing but in summary, data allegedly taken from Accor was published to a popular hacking forum and the headlines inevitably followed. However,

Continue reading Weekly Update 395