Remove setting-the-bar-for-government-access-to-have-i-been-pwned
article thumbnail

Is India's Aadhaar System Really "Hack-Proof"? Assessing a Publicly Observable Security Posture

Troy Hunt

It's operating in an era of increasingly large repositories of personal data held by both private companies and governments alike. But there's been one claim more than any other that's really caught my eye, and it's this one: Troy, meet @UIDAI and @NandanNilekani. (@agarwal_mohit) January 5, 2018. billion locals' data.

Hacking 279
article thumbnail

Setting the Bar for Government Access to Have I Been Pwned

Troy Hunt

Over the last 4 years, I've onboarded 28 national government CERTs onto Have I Been Pwned (HIBP) and given them free and open access to APIs that enable them to query and monitor their gov domains. As interest from govs has grown, it's caused me to ponder: who am I willing to give access to?