Sponsored by:

Troy Hunt

Hi, I'm Troy Hunt, I write this blog, create courses for Pluralsight and am a Microsoft Regional Director and MVP who travels the world speaking at events and training technology professionals

New Pluralsight Course: Modern Web Security Patterns

I was chatting to some folks at a bank just the other day about a bunch of modern web security standards. Whilst this blog post is about a Pluralsight course I created with Lars Klint, it only really hit me during that bank conversation just how much there is to take onboard when it comes to securing things in the browser today. Let me paraphrase: Bank: We're thinking of using SRI to protect malicious modification of scripts we load in from a partner. Me: Ok, but be conscious that means they can never change those scripts without you first modifying the integrity attribute on your script tags and you need time to push that out so as not to break...

Social Media Thread-Hijacking is Nothing More Than Targeted Spam

I have a vehement dislike of spam. Right there, that's something you and I have in common because I'm yet to meet a person who says "well actually, I find those Viagra emails I receive every day kinda useful". We get bombarded by spam on a daily basis and quite rightly, people get kinda cranky when they have to deal with it; it's an unwanted invasion that takes a little slice of unnecessary mental processing each time we see it. Sure, junk mail filters catch a lot of it, but even the best implementations will still let a few slip through now and then. But for the most part, spam is indiscriminate; you're on a list so bam...

Weekly Update 82 (Honolulu Edition)

I'm in Honolulu! And I apologise in advance for the audio quality - the background noise is air conditioning units in the hotel and I didn't realise quite how much sound they make until I listened to the audio afterwards. Next week I'll be home and back to a quality audio setup. Regardless, I did pump out a shorter update with a bunch of bits and pieces that popped up during the week. Firstly, the obnoxious behaviour that is Twitter thread hijacking (think of everything you hate about spam, just distilled down to 280 characters). I also caught up with a bunch of people from 1Password during my time in Hawaii and fleshed out how I'm going to be clearer...

Microsoft Regional Director (Redux)

I received a very nice email this week: Congratulations, your nomination has been accepted to the Microsoft Regional Director program! I am pleased to welcome you back to this worldwide community of technology thought leaders and thank you for being a part of this community. Just over 2 years ago, I first became a Microsoft Regional Director. This is a role that has meant a great deal to me over that time; it's not one you can sit an exam for and no amount of money will buy you one either. Like the Microsoft Most Valuable Professional (MVP) role I've had since 2011, it's one that only comes from being an active member of the technology community and contributing to...

Weekly Update 81 (Hawaii Edition)

We're in Hawaii! "We" being Scott Helme and myself and we're here for the Loco Moco Sec conference which has been a heap of fun (the location may have played a part in that...) And what a location: Scott joined me for this week's update and we were fresh out of a great talk from the Google Chrome Security PM so have a bit to share there about changes coming to the browser. And then, T-Mobile - whoa! Just read the thread I link to in the references below (get popcorn - this one is a crazy ride). We also talk a bit about not deleting our Facebook accounts and being a bit pragmatic about choosing what you...

Weekly Update 80

It's a MASSIVE weekly update! The big news for me this week is the 1Password partnership and I've really tried to share more about how I came to the decision to work with them in this video. I've been so cautious with the way I've managed the image of HIBP to ensure it's always positioned in the right light and I wanted to delve more into that thinking here. As I say in the video, I'm really happy with the feedback so far and I've "liked" a bunch of the responses so check out my Twitter profile to see what people are saying about the partnership. But that was just one of the big things this week, there's...

Have I Been Pwned is Now Partnering With 1Password

The penny first dropped for me just over 7 years ago to the day: The only secure password is the one you can't remember. In an era well before the birth of Have I Been Pwned (HIBP), I was doing a bunch of password analysis on data breaches and wouldn't you know it - people are terrible at creating passwords! Of course, we all know that but it's interesting to look back on that post all these years later and realise that unfortunately, nothing has really changed. The strength of most passwords is terrible. Then they get reused. Everywhere. That post was my own personal wakeup call; it was the very point where I observed that what we all needed...

Aussie Telcos are Failing at Some Fundamental Security Basics

Recently, I've witnessed a couple of incidents which have caused me to question some pretty fundamental security basics with our local Aussie telcos, specifically Telstra and Optus. It began with a visit to the local Telstra store earlier this month to upgrade a couple of phone plans which resulted in me sitting alone by this screen whilst the Telstra staffer disappeared into the back room for a few minutes: Is it normal for @Telstra to display customer passwords on publicly facing terminals in their stores? (You know, the same password people give their bank.) This is the user-selected password used for identity verification with store customers wandering past it. pic.twitter.com/KiaGNKhaig— Troy Hunt (@troyhunt) March 1, 2018...

A Scammer Tried to Scare Me into Buying Their Security Services - Here's How It Went Down

Here's the tl;dr - someone named "Md. Shofiur R" found troyhunt.com on a "free online malware scanner" and tried to scare me into believing my site had security vulnerabilities then shake me down for a penetration test. It didn't work out so well for him, here's the blow-by-blow account of things then I'll add some more thoughts afterwards: Should I respond? 😂 pic.twitter.com/lifCZRcICF— Troy Hunt (@troyhunt) March 20, 2018 I couldn’t help myself pic.twitter.com/zvx3myyItn— Troy Hunt (@troyhunt) March 20, 2018 Ooh, he’s good! Suggestions? This feels like it’ll be more fun crowd-sourced 😎 pic.twitter.com/i2EFDFgLem— Troy Hunt (@troyhunt) March 20, 2018 Your...

Weekly Update 79

Home again which means more time to blog and per the intro to this week's update, time to catch up on how HIBP is tracking. Here's the 2 tweets with some stats I mention at the start of this week's update: It's been almost a month since I launched Pwned Passwords V2. In that time, @cloudflare has served 156TB from their cache thus keeping the traffic off my origin. Thanks guys, this would have been a hard discussion to have with the wife otherwise! pic.twitter.com/KUX0kXwjCo— Troy Hunt (@troyhunt) March 21, 2018 Also, just got the bill for the @AzureFunctions which drive the Pwned Passwords API. Because 80%+ of requests are served from @Cloudflare'...