Google Adds Password Checkup Feature to Chrome Browser

Google’s new password checkup tool joins other similar services including Have I Been Pwned and Mozilla’s Firefox Monitor. Continue reading Google Adds Password Checkup Feature to Chrome Browser

Welcoming the Irish Government to Have I Been Pwned

Presently sponsored by: strongDM-see why Splunk’s CISO says “strongDM enables you to see what happens, replay & analyze incidents. You can’t get that anywhere else”

Over the last year and a bit I’ve been working to make more data in HIBP freely available to governments around the world that want to monitor their own exposure in data breaches. Like the rest of us, governments regularly rely on services that fall victim to attacks resulting in

Continue reading Welcoming the Irish Government to Have I Been Pwned

Is there a reason why I should not use the HaveIBeenPwned API to warn users about exposed passwords?

There’s lots of talk about the HaveIBeenPwned password checker which can securely tell users if their password appears in one of their known data dumps of passwords.

This tool has a publically available API behind it which w… Continue reading Is there a reason why I should not use the HaveIBeenPwned API to warn users about exposed passwords?

Authentication and the Have I Been Pwned API

Presently sponsored by: Shape Connect: Captcha is no longer enough. Shape Connect blocks automation & improves security instantly, with a 30 minute implementation.

The very first feature I added to Have I Been Pwned after I launched it back in December 2013 was the public API. My thinking at the time was that it would make the data more easily accessible to more people to go and do awesome things; build mobile clients,

Continue reading Authentication and the Have I Been Pwned API