Weekly Update 406

Presently sponsored by: Push Security. Stop identity attacks with a browser-based agent that detects and prevents account takeover. Try it free now.

Why does it need to be a crazy data breach week right when I’m struggling with jet lag?! I came home from Europe just as a bunch of the Snowflake-sourced breaches started being publicly dumped, and things went a little crazy. Lots of data to review, lots of

Continue reading Weekly Update 406

Weekly Update 401

Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite

Ah, episode 401, the unauthorised one! Ok, that was terrible, but what’s not terrible is finally getting some serious dev resources behind HIBP. I touch on it in the blog post but imagine all the different stuff I have to spread myself across to run this thing, and

Continue reading Weekly Update 401

Weekly Update 400

Presently sponsored by: Kolide is an endpoint security solution for teams that want to meet SOC2 compliance goals without sacrificing privacy. Learn more here.

This is the 400th time I’ve sat down in front of the camera and done one of these videos. Every single week since the 23rd of September in 2016 regardless of location, health, stress and all sorts of other crazy things that have gone on in my life

Continue reading Weekly Update 400

Weekly Update 399

Presently sponsored by: Kolide believes that maintaining endpoint security shouldn’t mean compromising employee privacy. Check out our manifesto: Honest Security.

The Post Millennial breach in this week’s video is an interesting one, most notably because of the presence of the mailing lists. Now, as I’ve said in every piece of communication I’ve put out on this incident, the lists are what whoever defaced the

Continue reading Weekly Update 399

Weekly Update 398

Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite

How many different angles can you have on one data breach? Facial recognition (which probably isn’t actual biometrics), gambling, offshore developers, unpaid bills, extortion, sloppy password practices and now, an arrest. On pondering it more after today’s livestream, it’s the unfathomable stupidity of publishing

Continue reading Weekly Update 398

Weekly Update 397

Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite

Banks. They screw us on interest rates, they screw us on fees and they screw us on passwords. Remember the old “bank grade security” adage? I took this saying to task almost a decade ago now but it seems that at least as far as password advice goes,

Continue reading Weekly Update 397

Weekly Update 396

Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite

“More Data Breaches Than You Can Shake a Stick At”. That seems like a reasonable summary and I suggest there are two main reasons for this observation. Firstly, there are simply loads of breaches happening and you know this already because, well, you read my stuff! Secondly, There

Continue reading Weekly Update 396

Weekly Update 395

Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite

Data breach verification: that seems like a good place to start given the discussion in this week’s video about Accor. Watch the vid for the whole thing but in summary, data allegedly taken from Accor was published to a popular hacking forum and the headlines inevitably followed. However,

Continue reading Weekly Update 395