You’ll Soon Be Able to Sign in to Have I Been Pwned (but Not Login, Log in or Log On)

Presently sponsored by: 1Password Extended Access Management: Secure every sign-in for every app on every device.

How do seemingly little things manage to consume so much time?! We had a suggestion this week that instead of being able to login to the new HIBP website, you should instead be able to log in. This initially confused me because I’ve been used to logging on

Continue reading You’ll Soon Be Able to Sign in to Have I Been Pwned (but Not Login, Log in or Log On)

Weekly Update 446

Presently sponsored by: Malwarebytes Browser Guard blocks phishing, ads, scams, and trackers for safer, faster browsing

After an unusually long day of travelling from Iceland, we’ve finally made it to the land of Guinness, Leprechauns, and a tax haven for tech companies. This week, there are a few more lessons from the successful phish against me the previous week, and in happier news, there

Continue reading Weekly Update 446

A Sneaky Phish Just Grabbed my Mailchimp Mailing List

Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite

You know when you’re really jet lagged and really tired and the cogs in your head are just moving that little bit too slow? That’s me right now, and the penny has just dropped that a Mailchimp phish has grabbed my credentials, logged into my account

Continue reading A Sneaky Phish Just Grabbed my Mailchimp Mailing List

Posted in Uncategorized

Soft-Launching and Open Sourcing the Have I Been Pwned Rebrand

Presently sponsored by: 1Password Extended Access Management: Secure every sign-in for every app on every device.

Designing the first logo for Have I Been Pwned was easy: I took a SQL injection pattern, wrote “have i been pwned?” after it and then, just to give it a touch of class, put a rectangle with rounded corners around it:

Job done! I mean really, what

Continue reading Soft-Launching and Open Sourcing the Have I Been Pwned Rebrand

Weekly Update 442

Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite

We survived the cyclone! That was a seriously weird week with lots of build-up to an event that last occurred before I was born. It’d been 50 years since a cyclone came this far south, and the media was full of alarming predictions of destruction. In the end,

Continue reading Weekly Update 442

We’re Backfilling and Cleaning Stealer Logs in Have I Been Pwned

Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite

I think I’ve finally caught my breath after dealing with those 23 billion rows of stealer logs last week. That was a bit intense, as is usually the way after any large incident goes into HIBP. But the confusing nature of stealer logs coupled with an overtly long

Continue reading We’re Backfilling and Cleaning Stealer Logs in Have I Been Pwned

Weekly Update 441

Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite

Processing data breaches (especially big ones), can be extremely laborious. And, of course, everyone commenting on them is an expert, so there’s a heap of opinions out there. And so it was with the latest stealer logs, a corpus of data that took the better part of a

Continue reading Weekly Update 441