favs.blue
  1. 3

    This is such cool analysis of PIN in @haveibeenpwned.com's Pwned Passwords. Scroll through the page and watch the heat map change alongside the explanations of how people are creating (somewhat) predictable PINs: www.abc.net.au/news/2025-01...

    83 36
    Jan 27, 2025
  2. 5

    A few years ago, I wrote a book. It was the culmination of my most important posts and the stories behind them. Writing this book also helped keep me sane during insane times, and as of today, I'm giving it away for free 😊 www.troyhunt.com/pwned-the-bo...

    62 22
    Dec 6, 2024
  3. 8

    I recently had a great meetup with @ncsc.gov.uk largely discussing the importance of passkeys. "I should write up a blog post for normal people", I suggested, then went back to my hotel and got phished 🤦‍♂️ Finally, here's that blog post: www.troyhunt.com/passkeys-for...

    44 16
    May 5, 2025
  4. 10

    Well this just made life a lot easier - ChatGPT hash cracking!

    74 14
    Oct 3, 2025
  5. 11

    Finally, after 11 years and 97 days, @haveibeenpwned.com has a new look! Today, we're "soft launching" the rebrand, that is we're giving everyone a look and welcoming contributions, but you won't see it on any publicly facing assets yet. What do you think? www.troyhunt.com/soft-launchi...

    97 13
    Mar 11, 2025
  6. 12

    This has been an extraordinary set of data to process: 1.3B unique passwords, 2B unique email addresses (including mine 😭) and almost 3M of our @haveibeenpwned.com subscribers in there. It’s been weeks of processing to get this loaded, and finally, it’s done www.troyhunt.com/2-billion-em...

    51 11
    Nov 6, 2025
  7. 13

    Occasionally, someone takes issue with me flagging a data breach as "sensitive" such that the email addresses can't be publicly searched because they want to dox the users. That's a *really* bad idea, for many reasons: www.troyhunt.com/who-decides-...

    36 10
    Jan 13, 2026
  8. 16

    10 years ago today, I started a pet project with a stupid name. Like all my previous projects, I expected it to scratch an itch and then fail miserably. But Have I Been Pwned didn't do that, not by a long shot. A decade later here we are! 🎂 www.troyhunt.com/a-decade-of-...

  9. 17

    We're very happy to help the amazing people at @cern.bsky.social gain greater insights into the impact of data breaches on the work they do. CERN is the first intergovernmental organisation we've onboarded to @haveibeenpwned.com, here's the background: www.troyhunt.com/welcoming-ce...

  10. 19

    Can you believe it’s ten years to the day since the Ashley Madison data breach hit the news?! It’s still arguably the most impactful, most widely publicised data breach in history. krebsonsecurity.com/2015/07/onli...

  11. 23

    I've had this dumb report too many times, and Bruce has finally tipped me over the edge. @haveibeenpwned.com is a real service that looks up email addresses in actual data breaches, but some people don't understand what an email address actually is www.troyhunt.com/why-does-hav...

  12. 24

    It’s not a real data breach unless it causes people serious harm. Words to that effect are rife throughout privacy reforms that continue to prioritise the responsible organisation over the impacted individuals www.ashurst.com/en/insights/...

  13. 25

    I'm looking for some contacts at companies that provide identity protection services, any followers out there? Further, have you had good experiences with any specific companies? There are some product placement opportunities we're exploring in the updated @haveibeenpwned.com site.