Home Assistant + Ubiquiti + AI = Home Automation Magic

Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite

It seems like every manufacturer of anything electrical that goes in the house wants to be part of the IoT story these days. Further, they all want their own app, which means you have to go to gazillions of bespoke software products to control your things. And they’re

Continue reading Home Assistant + Ubiquiti + AI = Home Automation Magic

Weekly Update 466

Presently sponsored by: 1Password Extended Access Management: Secure every sign-in for every app on every device.

I’m fascinated by the unwillingness of organisations to name the “third party” to which they’ve attributed a breach. The initial reporting on the Allianz Life incident from last month makes no mention whatsoever of Salesforce, nor does any other statement I can find from

Continue reading Weekly Update 466

That 16 Billion Password Story (AKA “Data Troll”)

Presently sponsored by: Malwarebytes Browser Guard blocks phishing, ads, scams, and trackers for safer, faster browsing

Spoiler: I have data from the story in the title of this post, it’s mostly what I expected it to be, I’ve just added it to HIBP where I’ve called it “Data Troll”, and I’m going to give everyone a

Continue reading That 16 Billion Password Story (AKA “Data Troll”)

Posted in Uncategorized

Get Pwned, Get Local Advice From a Trusted Gov Source

Presently sponsored by: Malwarebytes Browser Guard blocks phishing, ads, scams, and trackers for safer, faster browsing

We were recently travelling to faraway lands, doing meet and greets with gov partners, when one of them posed an interesting idea:

What if people from our part of the world could see a link through to our local resource on data breaches provided by the gov?

Initially, I was

Continue reading Get Pwned, Get Local Advice From a Trusted Gov Source

Welcoming Guardio to Have I Been Pwned’s Partner Program

Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite

I’m often asked if cyber criminals are getting better at impersonating legitimate organisations in order to sneak their phishing attacks through. Yes, they absolutely are, but I also argue that the inverse is true too: legitimate organisations frequently communicate in ways that are indistinguishable from a phishing attack!

Continue reading Welcoming Guardio to Have I Been Pwned’s Partner Program

Weekly Update 463

Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite

I’ve listened to a few industry podcasts discussing the Tea app breach since recording, and the thing that really struck me was the lack of discussion around the privacy implications of the service before the breach. Here was a tool where people were non-consensually uploading photos of others

Continue reading Weekly Update 463

Weekly Update 462

Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite

This will be the title of the blog post: “Court Injunctions are the Thoughts and Prayers of Data Breach Response”. It’s got a nice ring to it, and it resonates so much with the response to other disasters where the term is offered as a platitude

Continue reading Weekly Update 462

11 Years of Microsoft Regional Director and 15 Years of MVP

Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite

I often wonder how much people in other professions genuinely love the industry they’re in to the point that they’d do it regardless of the money. I’m sure there are examples, but I wonder how many lawyers look forward to doing something in the

Continue reading 11 Years of Microsoft Regional Director and 15 Years of MVP