Remove listing tags uk-and-i
article thumbnail

A Decade of Have I Been Pwned

Troy Hunt

A decade ago to the day, I published a tweet launching what would surely become yet another pet project that scratched an itch, was kinda useful to a few people but other than that, would shortly fade away into the same obscurity as all the other ones I'd launched over the previous couple of decades: It's alive! "Have

article thumbnail

The Legitimisation of Have I Been Pwned

Troy Hunt

There's no way to sugar-coat this: Have I Been Pwned (HIBP) only exists due to a whole bunch of highly illegal activity that has harmed many individuals and organisations alike. This has changed most fundamentally in the last year and a bit so let me start there. The Industry Cleaned Up a Lot in 2017.

Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

Lazarus targets defense industry with ThreatNeedle

SecureList

Google TAG has recently published a post about a campaign by Lazarus targeting security researchers. We named Lazarus the most active group of 2020. We’ve observed numerous activities by this notorious APT group targeting various industries. The group has changed target depending on the primary objective.

Malware 133
article thumbnail

Is India's Aadhaar System Really "Hack-Proof"? Assessing a Publicly Observable Security Posture

Troy Hunt

Now, I don't want to enter the debate about whether Aadhaar should exist in the first place, that's a much more nuanced discussion. But claiming the service is "hack-proof", that's something I definitely have an issue with. Sooner or later, big repositories of data will be abused. They claim that they're hack-proof.

Hacking 279
article thumbnail

The JavaScript Supply Chain Paradox: SRI, CSP and Trust in Third Party Libraries

Troy Hunt

I know, we're all shocked but bear with me because it's an important part of the narrative of this post. This tag was in the source code over at secure.donaldjtrump.com/donate-homepage yet it was pulling script directly off Igor Escobar's GitHub repository for the project. And the UK's National Health Service. Until now.