Welcoming the Ukrainian Government to Have I Been Pwned

Presently sponsored by: Credential stuffing is currently the biggest threat to organisations, find out how you can protect your network right now with safepass.me

Another month, another national government to bring onto Have I Been Pwned. This time it’s the Ukrainian National Cybersecurity Coordination Center who now has access to monitor all their government domains via API domain search, free of charge.

The Ukraine is now the 13th government to be onboarded to HIBP’s

Continue reading Welcoming the Ukrainian Government to Have I Been Pwned

The Facebook Phone Numbers Are Now Searchable in Have I Been Pwned

Presently sponsored by: Credential stuffing is currently the biggest threat to organisations, find out how you can protect your network right now with safepass.me

The headline is pretty self-explanatory so in the interest of time, let me just jump directly into the details of how this all works. There’s been huge interest in this incident, and I’ve seen near-unprecedented traffic to Have I Been Pwned (HIBP) over the last couple of days, let me

Continue reading The Facebook Phone Numbers Are Now Searchable in Have I Been Pwned

Home Assistant, Pwned Passwords and Security Misconceptions

Presently sponsored by: Get a FREE password audit on your Active Directory users with pwncheck from safepass.me

Two of my favourite things these days are Have I Been Pwned and Home Assistant. The former is an obvious choice, the latter I’ve come to love as I’ve embarked on my home automation journey. So, it was with great pleasure that I saw the two integrated recently:

Continue reading Home Assistant, Pwned Passwords and Security Misconceptions

Gab Has Been Breached

Presently sponsored by: MEGA – The world’s largest provider of zero-knowledge E2EE cloud storage plus chat. Join 200m others who enjoy privacy – try MEGA for free.

I’ve investigated hundreds of data breaches over the years (there are 514 of them in Have I Been Pwned as I write this), and for the most part, the situation with Gab is just another day on the internet. But Gab is also different, having grown dramatically in recent months

Continue reading Gab Has Been Breached

Welcoming the Portuguese Government to Have I Been Pwned

Presently sponsored by: The world’s first company to bring privacy to the internet with zero-knowledge encrypted cloud storage. Try MEGA free and protect your data!

I’m pleased to welcome the first new government onto Have I Been Pwned for 2021, Portugal. The Portuguese CSIRT, CERT.PT, now has full and free access to query their government domains across the entire scope of data in HIBP.

This is now the 12th government onboarded to HIBP and

Continue reading Welcoming the Portuguese Government to Have I Been Pwned

Creating a LaMetric App with Cloudflare Workers and KV

Presently sponsored by: 1Password is a secure password manager and digital wallet that keeps you safe online

I had this idea out of nowhere the other day that I should have a visual display somewhere in my office showing how many active Have I Been Pwned (HIBP) subscribers I presently have. Why? I’m not sure exactly, it just seemed like a good idea at the time. Perhaps

Continue reading Creating a LaMetric App with Cloudflare Workers and KV

Inside the Cit0Day Breach Collection

Presently sponsored by: Join the Microsoft Reactor community for workshops and events to expand your skillset across a range of technologies and topics

It’s increasingly hard to know what to do with data like that from Cit0Day. If that’s an unfamiliar name to you, start with Catalin Cimpanu’s story on the demise of the service followed by the subsequent leaking of the data. The hard bit for me is figuring out whether it’s

Continue reading Inside the Cit0Day Breach Collection

Welcoming the Canadian Government to Have I Been Pwned

Presently sponsored by: SecurityFWD. A brand new YouTube show from Varonis. Watch Episode 1: How Far can Wi-Fi Travel?

Following in the footsteps of many other national governments before them, I’m very happy to welcome the Canadian Centre for Cyber Security to Have I Been Pwned. The Canadian Centre for Cyber Security now has full and free access to query all Canadian federal government domains across both past and

Continue reading Welcoming the Canadian Government to Have I Been Pwned