Happy birthday @haveibeenpwned.com! 11 years today, and now with its very own Bluesky account 😊 www.troyhunt.com/introducing-...
It finally happened - I got phished. Impact is limited to the Mailchimp mailing list for my blog, brief blog post with details here and more to come later: www.troyhunt.com/a-sneaky-phi...
Finally, after 11 years and 97 days, @haveibeenpwned.com has a new look! Today, we're "soft launching" the rebrand, that is we're giving everyone a look and welcoming contributions, but you won't see it on any publicly facing assets yet. What do you think? www.troyhunt.com/soft-launchi...
Great outcome by our global law enforcement partners, that's some big numbers: "at least 40,000 phishing domains linked to LabHost, which had some 10,000 users worldwide". Let's make those phished passwords useless, they're now all in @haveibeenpwned.com: www.europol.europa.eu/media-press/...
This is such cool analysis of PIN in @haveibeenpwned.com's Pwned Passwords. Scroll through the page and watch the heat map change alongside the explanations of how people are creating (somewhat) predictable PINs: www.abc.net.au/news/2025-01...
So… what’s everyone doing over here now? Twitter exodus? Sick of Mastodon? Other?
I'm going to try posting more here that previously would have gone to X when there was a more active audience, hope some of the engagement I saw there over so many years has simply moved here. Let's see 🙂
Happy birthday @haveibeenpwned.com! 12 years ago today, I pushed out a blog post launching a little data breach search tool, and life changed forever. Reading the post again now, did I get it right? 😎 www.troyhunt.com/introducing-...
After a gargantuan effort, the all-new @haveibeenpwned.com brand and website is now officially live! www.troyhunt.com/have-i-been-...
A few years ago, I wrote a book. It was the culmination of my most important posts and the stories behind them. Writing this book also helped keep me sane during insane times, and as of today, I'm giving it away for free 😊 www.troyhunt.com/pwned-the-bo...
I'm writing up a blog post called "Passkeys for Normal People", which is a non-trivial exercise. For example, whilst LinkedIn "supports" passkeys, it doesn't seem to allow using them as a second factor *or* a sole factor, so you're still left with passwords and OTPs. Correct?
10 years ago today, I started a pet project with a stupid name. Like all my previous projects, I expected it to scratch an itch and then fail miserably. But Have I Been Pwned didn't do that, not by a long shot. A decade later here we are! 🎂 www.troyhunt.com/a-decade-of-...
Going to try and roll to a handle on troyhunt.com so just in case stuff starts to look weird, that’d be my fault
Today, on @haveibeenpwned.com's 11th birthday, I'm happy to welcome the Armenian National Computer Incident Response Team as the 37th government to have free and open access to their gov domains. More here: www.troyhunt.com/welcoming-th...
This has been an extraordinary set of data to process: 1.3B unique passwords, 2B unique email addresses (including mine 😭) and almost 3M of our @haveibeenpwned.com subscribers in there. It’s been weeks of processing to get this loaded, and finally, it’s done www.troyhunt.com/2-billion-em...
I'm seriously considering just an outright ban on resellers buying @haveibeenpwned.com subscriptions for customers. It's just constant dramas, support overhead, obnoxious responses and confusion. What are customers actually getting from resellers, other than *massive* price markups?
Working on the @haveibeenpwned.com challenge coin, are we on the right track? Other side would be much more formal (new logo), what would you like to see?
Social media engagement on the big platforms has really changed the last few years. A lot of people I connected with on X left, Mastodon never really seems to have hit its stride, LinkedIn has a lot more professional engagement and FB a lot more casual stuff. How are you all finding Bsky?
I recently had a great meetup with @ncsc.gov.uk largely discussing the importance of passkeys. "I should write up a blog post for normal people", I suggested, then went back to my hotel and got phished 🤦♂️ Finally, here's that blog post: www.troyhunt.com/passkeys-for...
It sucked getting phished, but I couldn’t be happier with the community responses and positive outcomes from sharing this experience 😊
I've had this dumb report too many times, and Bruce has finally tipped me over the edge. @haveibeenpwned.com is a real service that looks up email addresses in actual data breaches, but some people don't understand what an email address actually is www.troyhunt.com/why-does-hav...
Yesterday, someone tried to sell an alleged data breach of JB Hi-Fi. The breach was a hoax, and it was dead simple to prove 😊 www.troyhunt.com/you-cant-tru...