Mastodon

MVP, round 6!

Each year since 2011, on April first (yeah, I know…), I’ve looked for one of these to land in my inbox and fortunately, this year didn’t disappoint: The MVP program has been an enormously fulfilling thing to be a part of these last five years. It’s been great for the connections I’ve made, the access to folks in Microsoft and the community engagements it’s lead to, particularly in my post-corporate life as an independent. Now yes, I’ve been misquoted as “Troy Hunt from Microsoft” many, many t...

The world needs more stupid security researchers – join me!

I love this Google Play store review of the NissanConnect app which had such terrible security issues recently [https://www.troyhunt.com/2016/02/controlling-vehicle-features-of-nissan.html]: > I may print and frame this: pic.twitter.com/P0hu7E08GQ [https://t.co/P0hu7E08GQ] — Troy Hunt (@troyhunt) March 17, 2016 [https://twitter.com/troyhunt/status/710604327186931712] I join a long line of stupid security folks who’ve messed things up for other people. Sometimes people have been unable to purc...

New Pluralsight course: Ethical Hacking, Denial of Service

I’ve just launched my latest Pluralsight course titled Ethical Hacking, Denial of Service [https://app.pluralsight.com/library/courses/ethical-hacking-denial-service/table-of-contents] but before I explain what’s in it, let’s kick off with some trivia: DDoS attacks have increased massively in size in recent years: This is from Arbor Networks’ latest Worldwide Infrastructure Security Report [https://www.arbornetworks.com/images/documents/WISR2016_EN_Web.pdf] and that was current in October wh...

Understanding CSRF, the video tutorial edition

Cross site request forgery is one of those attacks which remains enormously effective yet is frequently misunderstood. I’ve been running a bunch of security workshops for web developers around the globe recently and this is one of the topics we cover that often results in blank stares when I first ask about it. It usually unfolds that the developers have multiple resources at risk of a CSRF attack and if it’s not a classic web form style resource, then it’s frequently an API somewhere (you’re pa...

Request for feedback: Organisations using “Have I been pwned” data

Working on Have I been pwned [https://haveibeenpwned.com/] (HIBP), I come across a lot of interesting things. Interesting people dealing in data breaches, interesting vulnerabilities in systems which have been compromised and interesting requests from people wanting the data. In fact, I was getting so many requests for data I ended up writing No, I cannot share data breaches with you [https://www.troyhunt.com/2015/10/no-i-cannot-share-data-breaches-with-you.html] where I very explicitly laid out...

How your data is collected and commoditised via “free” online services

I get a lot of people popping up with data breaches for Have I been pwned [https://haveibeenpwned.com/] (HIBP). There’s an interesting story in that itself actually, one I must get around to writing in the future as folks come from all sorts of different backgrounds and offer up data they’ve come across in various locations. Recently someone sent me a list of various data breaches they’d obtained, including this one: > InstantCheckmate 2015 - 80M entries On the surface of it, that’s a phenom...

The Australian Taxation Office scam call

I actually thought that once I didn’t bother connecting a landline after moving house recently, it would be the end of scam calls. I used to get them all the time – the ones where they’d call up and say you had viruses on your PC – and my recordings of those turned out to be rather popular [https://www.youtube.com/watch?v=kjKjyMKj3n4]. But today I had another call, although this one went a bit differently. First off, I missed a call in the morning from a Sydney landline number which was 02 6064...

Microsoft Regional Director

This was not what I was expecting earlier this week: > I am delighted to welcome you to the Microsoft Regional Director program! [https://lh3.googleusercontent.com/-4LX7MFBmD2M/VtgQGXTimKI/AAAAAAAAI5g/TAhUk372Arw/s1600-h/msrd-logo-192px-alpha2.png] More specifically, the nomination I received some weeks back was not what I expected and this week’s message was what I’d dared not get my hopes up too much about. A bit of context first – I’m not going to work for Microsoft and despite the ti...

Kids and Code: Conditions and loops

Last week I published the first post of Kids and Code [https://www.troyhunt.com/2016/02/kids-and-code-simple-programming-on.html] where I started recording the process of teaching my six-year-old son to code. We used code.org [https://code.org/] which is just awesome, specifically the Minecraft game which has just the right balance of difficulty, engagement and entertainment. It’s mostly dragging and dropping blocks which represent procedures, but it’s a great way of getting kids to think about...

Breaches, “Have I been pwned?”, password reuse, 1Password and good deeds

I spend a lot of time on Have I been pwned [https://haveibeenpwned.com/] (HIBP) which consists of both maintaining and building out the software with new features as well as obviously sourcing new data for it on a regular basis. I make it freely available to the community and some time ago at the suggestion of some of those who’d found it useful, I stood up a donations page [https://haveibeenpwned.com/Donate]. Whilst the service is cheap to run courtesy of Azure being pretty cost efficient, it’s...