Weekly Update 302

Presently sponsored by: Detack. Detect & prevent weak, leaked, shared passwords with EPAS, a patented, privacy compliant solution used in 40 countries. Try it free!

In a complete departure from the norm, this week’s video is the much-requested “cultural differences” one with Charlotte. No tech (other than my occasional plug for the virtues of JavaScript), but lots of experiences from both of us living and working in different parts of the

Continue reading Weekly Update 302

Understanding Have I Been Pwned’s Use of SHA-1 and k-Anonymity

Presently sponsored by: Detack. Detect & prevent weak, leaked, shared passwords with EPAS, a patented, privacy compliant solution used in 40 countries. Try it free!

Four and a half years ago now, I rolled out version 2 of HIBP’s Pwned Passwords that implemented a really cool k-anonymity model courtesy of the brains at Cloudflare. Later in 2018, I did the same thing with the email address search feature used by Mozilla, 1Password and

Continue reading Understanding Have I Been Pwned’s Use of SHA-1 and k-Anonymity

Weekly Update 300

Presently sponsored by: Meet compliance objectives in a remote-first world without resorting to rigid device management. Try Kolide for 14-days free!

Well, we’re about 2,000km down on this trip and are finally in Melbourne, which was kinda the point of the drive in the first place (things just escalated after that). The whole journey is going into a long tweet thread you can find below (or mute –

Continue reading Weekly Update 300

Weekly Update 299

Presently sponsored by: Varonis for Salesforce. Detect suspicious behavior and strengthen your Salesforce security posture. Try it free!

How on earth does an enterprise rack-mounted NAS not come with rails to actually install it in the rack?! So yeah, that’s what’s in the box, something that should have been in the original box and not in a separate purchase. Just to add to the

Continue reading Weekly Update 299

Welcoming the Indonesian Government to Have I Been Pwned

Presently sponsored by: Varonis for Salesforce. Detect suspicious behavior and strengthen your Salesforce security posture. Try it free!

Four years ago now, I started making domains belonging to various governments around the world freely searchable via a set of APIs in Have I Been Pwned. Today, I’m very happy to welcome the 33rd government, Indonesia! As of now, the Indonesian National CERT managed under the National

Continue reading Welcoming the Indonesian Government to Have I Been Pwned

Weekly Update 297

Presently sponsored by: Varonis for Salesforce. Protect Salesforce data from overexposure and cyberthreats. Try it free!

So I basically spent my whole day yesterday playing with Ubiquiti gear and live-tweeting the experience 😊 This was an unapologetically geeky pleasure and it pretty much dominates this week’s video but hey, it’s a fun topic. Still, there’s a bunch of data breach

Continue reading Weekly Update 297

Weekly Update 296

Presently sponsored by: Kolide provides endpoint security for teams that value privacy, transparency, and employee productivity. Try Kolide for free today!

Data breaches, 3D printing and passwords – just the usual variety of things this week. More specifically, that really cool Pwned Passwords downloader that I know a bunch of people have been waiting on, and now we’ve finally released. It hits the existing k-anonymity API over 1 million

Continue reading Weekly Update 296

Downloading Pwned Passwords Hashes with the HIBP Downloader

Presently sponsored by: Kolide provides endpoint security for teams that value privacy, transparency, and employee productivity. Try Kolide for free today!

Just before Christmas, the promise to launch a fully open source Pwned Passwords fed with a firehose of fresh data from the FBI and NCA finally came true. We pushed out the code, published the blog post, dusted ourselves off and that was that. Kind of – there was just

Continue reading Downloading Pwned Passwords Hashes with the HIBP Downloader

Posted in Uncategorized