Have I Been Pwned 2.0 is Now Live!

Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite

This has been a very long time coming, but finally, after a marathon effort, the brand new Have I Been Pwned website is now live!

Feb last year is when I made the first commit to the public repo for the rebranded service, and we soft-launched the new brand in

Continue reading Have I Been Pwned 2.0 is Now Live!

Welcoming the Malaysian Government to Have I Been Pwned

Presently sponsored by: 1Password Extended Access Management: Secure every sign-in for every app on every device.

Today, we welcome the 40th government onboarded to Have I Been Pwned’s free gov service, Malaysia. The NC4 NACSA (National Cyber Coordination and Command Centre of the National Cyber Security Agency) in Malaysia now has full access to query all their government domains via API, and monitor them

Continue reading Welcoming the Malaysian Government to Have I Been Pwned

After the Breach: Finding new Partners with Solutions for Have I Been Pwned Users

Presently sponsored by: Join Snyk’s May 15th event to discover how to establish a Security Champions program, bridging security and development

For many years, people would come to Have I Been Pwned (HIBP), run a search on their email address, get the big red “Oh no – pwned!” response and then… I’m not sure. We really didn’t have much guidance until we partnered with 1Password

Continue reading After the Breach: Finding new Partners with Solutions for Have I Been Pwned Users

Welcoming the Isle of Man Government to Have I Been Pwned

Presently sponsored by: Join Snyk’s May 15th event to discover how to establish a Security Champions program, bridging security and development

Today we welcome the 39th government and first self-governing British Crown Dependency to Have I Been Pwned, The Isle of Man. Their Office of Cyber-Security & Information Assurance (OCSIA) now has free and open access to query the government domains of their jurisdiction.

We’re delighted and encouraged to

Continue reading Welcoming the Isle of Man Government to Have I Been Pwned

Passkeys for Normal People

Presently sponsored by: Join Snyk’s May 15th event to discover how to establish a Security Champions program, bridging security and development

Let me start by very simply explaining the problem we’re trying to solve with passkeys. Imagine you’re logging on to a website like this:

And, because you want to protect your account from being logged into by someone else who may obtain your username and password,

Continue reading Passkeys for Normal People

Weekly Update 450

Presently sponsored by: Join Snyk’s May 15th event to discover how to establish a Security Champions program, bridging security and development

Looking back at this week’s video, it’s the AI discussion that I think about most. More specifically, the view amongst some that any usage of it is bad and every output is “slop”. I’m hearing that much more broadly lately, that AI

Continue reading Weekly Update 450

The Have I Been Pwned Alpine Grand Tour

Presently sponsored by: Join Snyk’s May 15th event to discover how to establish a Security Champions program, bridging security and development

I love a good road trip. Always have, but particularly during COVID when international options were somewhat limited, one road trip ended up, well, “extensive”. I also love the recent trips Charlotte and I have taken to spend time with many of the great agencies we’ve

Continue reading The Have I Been Pwned Alpine Grand Tour

Welcoming The Gambia National CSIRT to Have I Been Pwned

Presently sponsored by: Join Snyk’s May 15th event to discover how to establish a Security Champions program, bridging security and development

Today, we’re happy to welcome the Gambia National CSIRT to Have I Been Pwned as the 38th government to be onboarded with full and free access to their government domains. We’ve been offering this service for seven years now, and it enables national CSIRTs to gain

Continue reading Welcoming The Gambia National CSIRT to Have I Been Pwned