article thumbnail

Fixing Data Breaches Part 2: Data Ownership & Minimisation

Troy Hunt

Data Collection Should be Minimised, Not Maximisation. HIBP only needs an email address because that's all I'm looking for when someone appears in a data breach. Report URI needs a password as well because you need to be able to login. We don't even collect a name on either of those services because what good would it do?

article thumbnail

ChatGPT at work: how chatbots help employees, but threaten business

SecureList

While the first factor in most cases is a password, the second can be a one-time code sent by text/email or generated in a special app ; or it can be something far more complex, such as a hardware security key. The privacy policy has this to say about it: “Private mode: no data collection.