Remove authentication-and-the-have-i-been-pwned-api
article thumbnail

Data From The Qakbot Malware is Now Searchable in Have I Been Pwned, Courtesy of the FBI

Troy Hunt

Further, the passwords from the malware will shortly be searchable in the Pwned Passwords service which can either be checked online or via the API. Pwned Passwords is presently requested 5 and a half billion times each month to help organisations prevent people from using known compromised passwords.

Malware 329
article thumbnail

Home Assistant, Pwned Passwords and Security Misconceptions

Troy Hunt

Two of my favourite things these days are Have I Been Pwned and Home Assistant. So, it was with great pleasure that I saw the two integrated recently: always something. So, it was with great pleasure that I saw the two integrated recently: always something. How long until it hits the big "1B"? ??

Passwords 349
Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

Pwned Passwords, Version 5

Troy Hunt

Almost 2 years ago to the day, I wrote about Passwords Evolved: Authentication Guidance for the Modern Era. This wasn't so much an original work on my behalf as it was a consolidation of advice from the likes of NIST, the NCSC and Microsoft about how we should be doing authentication today. 3,768,890 passwords.

Passwords 233
article thumbnail

Police forces pipe 225 million pwned passwords into ‘Have I Been Pwned?’

Malwarebytes

On his blog , Troy Hunt has announced a major milestone in the ‘Have I Been Pwned?’ Have I Been Pwned?’. Have I Been Pwned?’ If you enter a password to see if it’s been pwned, it’s immediately turned into a SHA-1 hash and checked against the database.

Passwords 136
article thumbnail

Have I Been Pwned teams with FBI, gives open-source access to code

SC Magazine

The breach aggregator Have I Been Pwned, one of the most popular tools to test the real-world strength of passwords, made two significant announcements on Friday: A collaboration with the FBI to obtain new, hacked passwords, and contributing some of its code-base to the open-source community.

Passwords 113
article thumbnail

Trello Got a Scrape

Centraleyes

This week, a threat actor exploited an exposed Trello API, linking private email addresses with Trello accounts. Trello’s REST API, a valuable tool for developers, became the focal point of this breach. The accessibility of this API without authentication became a significant concern.

article thumbnail

Authentication and the Have I Been Pwned API

Troy Hunt

The very first feature I added to Have I Been Pwned after I launched it back in December 2013 was the public API. I highlighted 3 really important attributes at the time of launch: There is no authentication. One of those changed nearly 3 years ago now - I had to add a rate limit.