favs.blue
  1. 3

    Finally, after 11 years and 97 days, @haveibeenpwned.com has a new look! Today, we're "soft launching" the rebrand, that is we're giving everyone a look and welcoming contributions, but you won't see it on any publicly facing assets yet. What do you think? www.troyhunt.com/soft-launchi...

    97 13
    Mar 11, 2025
  2. 5

    This is such cool analysis of PIN in @haveibeenpwned.com's Pwned Passwords. Scroll through the page and watch the heat map change alongside the explanations of how people are creating (somewhat) predictable PINs: www.abc.net.au/news/2025-01...

    83 36
    Jan 27, 2025
  3. 6

    Well this just made life a lot easier - ChatGPT hash cracking!

    74 14
    Oct 3, 2025
  4. 7

    So… what’s everyone doing over here now? Twitter exodus? Sick of Mastodon? Other?

  5. 8

    Reply to @troyhunt.com

    I'm going to try posting more here that previously would have gone to X when there was a more active audience, hope some of the engagement I saw there over so many years has simply moved here. Let's see 🙂

  6. 10

    Reply to @troyhunt.com

    Done. That look ok now? Am I still here? 🙂

  7. 12

    A few years ago, I wrote a book. It was the culmination of my most important posts and the stories behind them. Writing this book also helped keep me sane during insane times, and as of today, I'm giving it away for free 😊 www.troyhunt.com/pwned-the-bo...

    62 22
    Dec 6, 2024
  8. 13

    I'm writing up a blog post called "Passkeys for Normal People", which is a non-trivial exercise. For example, whilst LinkedIn "supports" passkeys, it doesn't seem to allow using them as a second factor *or* a sole factor, so you're still left with passwords and OTPs. Correct?

  9. 14

    10 years ago today, I started a pet project with a stupid name. Like all my previous projects, I expected it to scratch an itch and then fail miserably. But Have I Been Pwned didn't do that, not by a long shot. A decade later here we are! 🎂 www.troyhunt.com/a-decade-of-...

  10. 16

    Perfect Aussie spring nights 😎

  11. 18

    This has been an extraordinary set of data to process: 1.3B unique passwords, 2B unique email addresses (including mine 😭) and almost 3M of our @haveibeenpwned.com subscribers in there. It’s been weeks of processing to get this loaded, and finally, it’s done www.troyhunt.com/2-billion-em...

    51 11
    Nov 6, 2025
  12. 19

    I'm seriously considering just an outright ban on resellers buying @haveibeenpwned.com subscriptions for customers. It's just constant dramas, support overhead, obnoxious responses and confusion. What are customers actually getting from resellers, other than *massive* price markups?

  13. 20

    Working on the @haveibeenpwned.com challenge coin, are we on the right track? Other side would be much more formal (new logo), what would you like to see?

  14. 21

    Social media engagement on the big platforms has really changed the last few years. A lot of people I connected with on X left, Mastodon never really seems to have hit its stride, LinkedIn has a lot more professional engagement and FB a lot more casual stuff. How are you all finding Bsky?

  15. 22

    I recently had a great meetup with @ncsc.gov.uk largely discussing the importance of passkeys. "I should write up a blog post for normal people", I suggested, then went back to my hotel and got phished 🤦‍♂️ Finally, here's that blog post: www.troyhunt.com/passkeys-for...

    44 16
    May 5, 2025
  16. 24

    I've had this dumb report too many times, and Bruce has finally tipped me over the edge. @haveibeenpwned.com is a real service that looks up email addresses in actual data breaches, but some people don't understand what an email address actually is www.troyhunt.com/why-does-hav...