Mastodon

Understanding account enumeration, the video tutorial edition

I've been running my Hack Yourself First workshop [https://www.troyhunt.com/workshops/] all over the world where I talk to software developers about various security risks which they then get to exploit firsthand. It's a lot of fun and very hands on and practical which inevitably means spending time looking at real world implementations of security. After running a couple of these workshops last week, I wrote Website enumeration insanity: how our personal data is leaked [https://www.troyhunt.co...

Website enumeration insanity: how our personal data is leaked

I've just wrapped up a couple of Hack Yourself First workshops [https://www.troyhunt.com/workshops/] down closer to home in Australia and true to usual form, attendees found some absolute zinger security implementations. Previous workshops have found various vulnerabilities ranging from realestate.com.au's lack of HTTPS in their Android app [https://www.troyhunt.com/are-your-apps-giving-one-device/] (pro tip: don't 301 HTTP requests to APIs!) to the one that really made headlines earlier this ye...

The "Have I been pwned" API, rate limiting and commercial use

It's almost 3 years ago now that I launched the Have I been pwned (HIBP) API [https://www.troyhunt.com/have-i-been-pwned-you-can-now-ask-api/] and made it free and unlimited. No dollars, no rate limits just query it at will and results not flagged as sensitive [https://haveibeenpwned.com/FAQs#SensitiveBreach] will be returned. Since then it's been called, well, I don't know how many times but at the least, it's well into the hundreds of millions if not billions. I've always been pretty clear on...

What you should and shouldn't worry about when you complete today's census

There's a lot of people getting themselves worked up about the Australian census [https://en.wikipedia.org/wiki/Census_in_Australia] whose five-yearly cycle falls due today. For the most part, it's like any other normal census we've done ever since I can remember, but what's changed this year is the duration for which names and addresses will be retained against the census answers. There are some good reasons to question the whole thing, plus some good reasons why it's really a non-event. Let m...

Stop the madness! Ridiculous security scare tactics revealed

You know the best way to sell security products? Scare the shit out of people. I mean make them really genuinely fearful that if they don't have the thing you're pushing that a bunch of nasty stuff will happen to them. It's the Donald Trump school of winning hearts and minds. Which brings me to CUJO [https://www.indiegogo.com/projects/cujo-the-smart-way-to-fight-hacking-security#/] , an Indiegogo campaign for a "security in a box" product. Strap yourself in and watch the video: Are we terrifie...

I wanna go fast: HTTPS' massive speed advantage

I tweeted this the other day, and the internet was not pleased: > HTTPS is slow. No - wait - is it HTTP that's slow?! https://t.co/T49GG7oCaK pic.twitter.com/cfnYOpXMWc [https://t.co/cfnYOpXMWc] — Troy Hunt (@troyhunt) July 8, 2016 [https://twitter.com/troyhunt/status/751317949349130240] In fact, a bunch of the internet was pretty upset. "It's not fair!", they cried. "You're comparing apples and oranges!", they raged. No, it's not fair, the internet is not fair. But that's just how the web i...

Why am I in a data breach for a site I never signed up to?

This question in the title of this post comes up after pretty much every data breach I load so I thought I'd answer it here once and for all then direct inquisitive Have I been pwned (HIBP) users when confusion ensues in the future. Let me outline a number of different root causes for the "why is my data on a site I never signed up to?" question. You forgot you signed up Let's start with the simplest explanation because it's often the correct one - you've simply forgotten you signed up. We leav...

Round 4 of Europe for 2016: More talks, more workshops

If you follow my Twitters, you may have noticed I can be a bit, well, "despondent" about the climate in Europe. No, not the whole Brexit political climate situation, I mean more like this: > Crowds of people in Birmingham waiting for summer before they go outside: pic.twitter.com/7ImjmCt4Bf [https://t.co/7ImjmCt4Bf] — Troy Hunt (@troyhunt) June 16, 2016 [https://twitter.com/troyhunt/status/743339389481189376] Yet I keep ending up back there so either it's my poor judgement or... I secretly en...

Getting to grips with cloud computing security on Pluralsight

Two of the things you'll have found me most frequently writing about on this blog are "cloud" and "security". Whilst the latter seems to have been what I've gravitated towards most in recent years, the former is something I'm very heavily involved in, particularly with my work on Have I been pwned [https://haveibeenpwned.com/] (HIBP). I'm enormously happy to see the very last course in the Ethical Hacking series [https://www.pluralsight.com/blog/tutorials/learning-path-ethical-hacking] I've been...

Introducing unverified breaches to Have I been pwned

Data breaches can be shady business. There's obviously the issue of sites being hacked in the first place which is not just shady, but downright illegal. Then there's the way this information is redistributed, the anonymous identities that deal with it and the various motives people have for bringing this data into the public eye. One of the constant challenges with the spread of data breaches is establishing what is indeed data hacked out of an organisation versus data from another source. We'...