If I’m honest, I was in two minds about adding additional stealer logs to HIBP. Even with the new feature to include the domains an email address appears against in the logs, my concern was that I’d get a barrage of “that’s useless information” messages like I normally do when I load stealer logs! Instead,…
Category: Weekly update
Global Security News, Weekly update
Weekly Update 434
This week I’m giving a little teaser as to what’s coming with stealer logs in HIBP and in about 24 hours from the time of writing, you’ll be able to see the whole thing in action. This has been a huge amount of work trawling through vast volumes of data and trying to make it…
Global Security News, Weekly update
Weekly Update 433
It sounds easy – “just verify people’s age before they access the service” – but whether we’re talking about porn in the US or Australia’s incoming social media laws, the reality is way more complex than that. There’s no unified approach across jurisdictions and even within a single country like Australia, the closest we’ve got…
Global Security News, Weekly update
Weekly Update 432
There’s a certain irony to the Bluesky situation where people are pushing back when I include links to X. Now, where have we seen this sort of behaviour before? 🤔 When I’m relying on content that only appears on that platform to add context to a data breach in HIBP and that content is freely…
Global Security News, Weekly update
Weekly Update 431
I fell waaay behind the normal video cadence this week, and I couldn’t care less 😊 I mean c’mon, would you rather be working or sitting here looking at this view after snowboarding through Christmas?! Christmas Day awesomeness in Norway 🇳🇴 Have a great one friends, wherever you are 🧑🎄 pic.twitter.com/F2FtcJYzRC — Troy Hunt (@troyhunt)…
Global Security News, Weekly update
Weekly Update 430
I’m back in Oslo! Writing this the day after recording, it feels like I couldn’t be further from Dubai; the temperature starts with a minus, it’s snowing and there’s not a supercar in sight. Back on business, this week I’m talking about the challenge of loading breaches and managing costs. A breach load immediately takes…
Global Security News, Weekly update
Weekly Update 429
A super quick intro today as I rush off to do the next very Dubai thing: drive a Lambo through the desert to go dirt bike riding before jumping in a Can-Am off-roader and then heading to the kart track for a couple of afternoon sessions. I post lots of pics to my Facebook account,…
Global Security News, Weekly update
Weekly Update 428
I wouldn’t say this is a list of my favourite breaches from this year as that’s a bit of a disingenuous term, but oh boy were there some memorable ones. So many of the incidents I deal with are relatively benign in terms of either the data they expose or the nature of the service,…
Global Security News, Weekly update
Weekly Update 427
I was going to write about how much I’ve enjoyed “tinkering” with the HIBP API, but somehow, that term doesn’t really seem appropriate any more for a service of this scale. On the contrary, we’re putting in huge amounts of effort to get this thing fast, stable, and sustainable. We could do the first two…
Global Security News, Weekly update
Weekly Update 426
I have absolutely no problem at all talking about the code I’ve screwed up. Perhaps that’s partly because after 3 decades of writing software (and doing some meaningful stuff along the way), I’m not particularly concerned about showing my weaknesses. And this week, I screwed up a bunch of stuff; database queries that weren’t resilient…
Global Security News, Weekly update
Weekly Update 425
This was a much longer than usual update, largely due to the amount of time spent discussing the Earth 2 incident. As I said in the video (many times!), the amount of attention this has garnered from both Earth 2 users and the company itself is incommensurate with the impact of the incident itself. It’s…
Global Security News, Weekly update
Weekly Update 424
I have really clear memories of listening to the Stack Overflow podcast in the late 2000’s and hearing Jeff and Joel talk about the various challenges they were facing and the things they did to overcome them. I just suddenly thought of that when realising how long this week’s video went for with no real…
Global Security News, Weekly update
Weekly Update 423
Firstly, my apologies for the minute and a bit of echo at the start of this video, OBS had somehow magically decided to start recording both the primary mic and the one built into my camera. Easy fix, moving on… During the livestream, I was perplexed as to why the HIBP DB was suddenly maxing…
Global Security News, Weekly update
Weekly Update 422
Apparently, Stefan and I trying to work stuff out in real time about how to build more efficient features in HIBP is entertaining watching! If I was to guess, I think it’s just seeing people work through the logic of how things work and how we might be able to approach things differently, and doing…
Global Security News, Weekly update
Weekly Update 421
It wasn’t easy talking about the Muah.AI data breach. It’s not just the rampant child sexual abuse material throughout the system (or at least requests for the AI to generate images of it), it’s the reactions of people to it. The tweets justifying it on the basis of there being noo “actual” abuse, the characterisation…
Global Security News, Weekly update
Weekly Update 420
Ok, the scenery here is amazing, but the real story is data breach victim notification. Charlotte and I wanted to do this one together today and chat about some of the things we’d been hearing from government and law enforcement on our travels, and the victim notification angle featured heavily. She reminded me of the…
Global Security News, Weekly update
Weekly Update 419
It’s not a green screen! It’s just a weird a weird hotel room in Pittsburgh, but it did make for a cool backdrop for this week’s video. We were there visiting our FBI friends after coming from Washington DC and a visit to CISA, the “America’s Cyber Defence Agency”. This week, I’m talking about those…