Enhancing Pwned Passwords Privacy by Exclusively Supporting Anonymity

Presently sponsored by: Netsparker – a scalable and dead accurate web application security solution. Scan thousands of web applications within just hours.

When I launched Pwned Passwords in August, I honestly didn’t know how much it would be used. I made 320M SHA-1 password hashes downloadable and also stood up an API to query the data “as a service” by either a plain text password or a SHA-1 hash. (Incidentally,…

Continue reading Enhancing Pwned Passwords Privacy by Exclusively Supporting Anonymity

Have I Been Pwned is Now Partnering With 1Password

Presently sponsored by: Do you desire peace of mind? The hackers don’t wait, secure your website and mobile apps with Gold Security today.

The penny first dropped for me just over 7 years ago to the day: The only secure password is the one you can’t remember. In an era well before the birth of Have I Been Pwned (HIBP), I was doing a bunch of password analysis on data breaches and wouldn’t…

Continue reading Have I Been Pwned is Now Partnering With 1Password

The Legitimisation of Have I Been Pwned

Presently sponsored by: Build scalable, reliable and secure cloud native applications with Tech Fabric

There’s no way to sugar-coat this: Have I Been Pwned (HIBP) only exists due to a whole bunch of highly illegal activity that has harmed many individuals and organisations alike. That harm extends all the way from those in data breaches feeling a sense of personal violation (that’s certainly how…

Continue reading The Legitimisation of Have I Been Pwned

Is it safe to check password against the HIBP Pwned Passwords API during account registration?

User registers account on a web app. Passwords are salted and hashed.
But is it safe to check the password against the HIBP Pwned Passwords API, before salting and hashing it? Of course the app uses TLS.

So if the password is found on any… Continue reading Is it safe to check password against the HIBP Pwned Passwords API during account registration?

The UK and Australian Governments Are Now Monitoring Their Gov Domains on Have I Been Pwned

Presently sponsored by: DigiCert: IoT security can be filled with overwhelming identity challenges. One simple change can help you address nearly every one of them.

If I’m honest, I’m constantly surprised by the extent of how far Have I Been Pwned (HIBP) is reaching these days. This is a little project I started whilst killing time in a hotel room in late 2013 after thinking “I wonder if people actually know where their data…

Continue reading The UK and Australian Governments Are Now Monitoring Their Gov Domains on Have I Been Pwned

I Wanna Go Fast: Why Searching Through 500M Pwned Passwords Is So Quick

Presently sponsored by: DigiCert: IoT security can be filled with overwhelming identity challenges. One simple change can help you address nearly every one of them.

In the immortal words of Ricky Bobby, I wanna go fast. When I launched Pwned Passwords V2 last week, I made it fast – real fast – and I want to talk briefly here about why that was important, how I did it and then how I’ve since shaved another…

Continue reading I Wanna Go Fast: Why Searching Through 500M Pwned Passwords Is So Quick