Mastodon

Don't tell people to turn off Windows Update, just don't

You know what really surprised me about this whole WannaCry ransomware problem [https://www.troyhunt.com/everything-you-need-to-know-about-the-wannacrypt-ransomware/]? No, not how quickly it spread. Not the breadth of organisations it took offline either and no, not even that so many of them hadn't applied a critical patch that landed a couple of months earlier. It was the reactions to this tweet that really surprised me: > Why is malware effective? Because of idiotic advice like this: "Stop Wi...

Everything you need to know about the WannaCry / Wcry / WannaCrypt ransomware

I woke up to a flood of news about ransomware today. By virtue of being down here in Australia, a lot happens in business hours around the world while we're sleeping but conversely, that's given me some time to collate information whilst everyone else is taking a break. The WannaCry incident is both new and scary in some ways and more of the same old stuff in others. Here's what I know and what the masses out there need to understand about this and indeed about ransomware in general. The ransom...

Weekly update 34

The big news this week has been dealing with that massive volume of data I loaded into HIBP a week ago. A combination of the mechanics of getting it loaded, the flood of feedback once I did and actually trying to prepare myself for upcoming talks has made it a bit of a crazy week. If I'm honest, I'm feeling a bit run down from it all and need to take it a bit easier before heading away in a couple of weeks' time. Be that as it may, this has been a full-on week and I've captured the highlights be...

Here are all the reasons I don't make passwords available via Have I been pwned

Over the last few days, I've loaded more than 1 billion new records into Have I been pwned(HIBP) [https://www.troyhunt.com/password-reuse-credential-stuffing-and-another-1-billion-records-in-have-i-been-pwned/] . As I describe in that blog post, this data was from two very large "combo lists", that is email address and password pairs created by malicious parties in order to help them break into other accounts reusing those credentials. In all, I sent about 440k email notifications and saw hundre...

Weekly update 33 (sunrise edition)

Wow, what a day! I got up at about 3:30 this morning and have been going non-stop dealing with the masses of feedback as a result of the billion-and-a-bit breached records I'm presently loading into HIBP. I talk about it in the blog post, but the "small" one of 458 million records is already loaded and as I type this, at about 17:30 Friday, the big one of almost 600M is still a long way off (probably mid-morning for me tomorrow). Anyway, between other commitments and the looong lead-time of uplo...

Password reuse, credential stuffing and another billion records in Have I been pwned

The short version: I'm loading over 1 billion breached accounts into HIBP. These are from 2 different "combo lists", collections of email addresses and passwords from all sorts of different locations. I've verified their accuracy (including my own record in one of them) and many hundreds of millions of the email addresses are not already in HIBP. Because of the nature of the data coming from different places, if you're in there then treat it as a reminder that your data is out there circulating...

Microsoft Flow + Azure Storage + WebJobs + MailChimp + Outlook

A few years back, I added a donations page to Have I been pwned (HIBP) [https://haveibeenpwned.com/Donate]. Now as I explained at the time, I didn't particularly need them to cover my hard-cash outgoings because I run the thing on a shoestring, but as I explain on that page, it takes a massive amount of effort. If people want to fling me a coffee or some beers, that's just great and I appreciate it enormously. Problem is, it's hard to individually show that appreciation. Especially during a busy...

Reckon you've seen some stupid security things? Here, hold my beer...

My mate Lars Klint shared this tweet the other day: > Your password is not unique. pic.twitter.com/ga4GwxtzrQ [https://t.co/ga4GwxtzrQ] — Lars Klint (@larsklint) April 16, 2017 [https://twitter.com/larsklint/status/853507749488975873] Naturally, I passed it on [https://twitter.com/troyhunt/status/853517036131041280] because let's face it, that's some crazy shit going on right there. To which the Twitters responded with equal parts abject horror and berating comments for not having already iden...

Weekly update 32

Home again and blog wise, it was a quiet week. I've been working on some new material you'll see next month as well as preparing for upcoming Europe travels where I've got a heap of events to get to. I've got a new Lenovo to show you in this update plus I do talk quite a bit about that one blog post on building out a Ubiquiti network for my brother and his family which I'm now kinda jealous of! All that and a few other things in the update below, I've got a few extra things in the works for next...

Wiring a home network from the ground-up with Ubiquiti

The title of this blog post is what many of us techie folks dream of - free reign to build your own home network! It might seem like a pretty geeky dream (ok, it is a pretty geeky dream), but the reality is that we're increasingly dependent on our home networks these days because of the amount of stuff we connect to them. That little consumer-grade combination modem and wireless access point your ISP gave you or the one you bought from the local PC store is going to struggle to provide fast, rel...