A big “thank you” to everyone who helped me troubleshoot the problem with my “Print Screen” button on the new PC. Try as we all might, none of us could figure out why it refused to bind to SnagIt and instead insisted on dumping the entire collection of screens to a file on the desktop.…
Category: Weekly update
Global Security News, Weekly update
Weekly Update 489
This week I’m in Hong Kong, and the day after recording, I gave the talk shown in the image above at INTERPOL’s Cybercrime Expert Group. I posted a little about this on Facebook and LinkedIn, but thought I’d expand on what really stuck with me after watching other speakers: the effort agencies are putting into…
Global Security News, Weekly update
Weekly Update 488
It’s the discussion about the reaction of some people in the UK regarding their impending social media ban for under 16s that bugged me most. Most noteably was the hand-waving around “the gov is just trying to siphon up all our IDs” and “this means everyone will have to show ID, not just under 16s”.…
Global Security News, Weekly update
Weekly Update 487
I thought Scott would cop it first when he posted about what his solar system really cost him last year. “You’re so gonna get that stupid AI-slop response from some people”, I joked. But no, he got other stupid responses instead! And I got the AI-slop responses! Draw your own conclusions on those comments, but…
Global Security News, Weekly update
Weekly Update 486
I’m in Oslo! Flighty is telling me I’ve flown in or out of here 43 times since a visit in 2014 set me on a new path professionally and, many years later, personally. It’s special here, like a second home that just feels… right. This week, the business end of things is about the WhiteDate…
Global Security News, Weekly update
Weekly Update 485
15 mins and 40 seconds. That’s how long it took to troubleshoot the first tech problem of 2026, and that’s how far you’ll need to skip through this video to hear the audio at normal volume. The problem Scott and I had is analogous to the troubleshooting so many of us do in our roles…
Global Security News, Weekly update
Weekly Update 484
I think the start of this week’s video really nailed it for the techies amongst us: shit doesn’t work, you change something random and now shit works and yu have no idea why 🤷♂️ Such was my audio this week and apoligise to those of you watching the video below for the first few mins…
Global Security News, Weekly update
Weekly Update 483
Building out an IoT environment is a little like the old Maslow’s Hierarchy of Needs. All the stuff on the top is only any good if all the stuff on the bottom is good, starting with power. This week, I couldn’t even get that right, but thankfully, sparky to rescue and ensuite underfloor heating disconnected,…
Global Security News, Weekly update
Weekly Update 482
Perhaps it’s just the time of year where we all start to wind down a bit, or maybe I’m just tired after another massive 12 months, but this week’s vid is way late. Ok, going away to the place that had just been breached (ironic!) didn’t help, but I think in general the pace we’ve…
Global Security News, Weekly update
Weekly Update 481
Twelve years (and one day) since launching Have I Been Pwned, it’s now a service that Charlotte and I live and breathe every day. From the first thing every morning to the last thing each day, from holidays to birthdays, in sickness and in heal… wait a minute – did we marry each other or…
Global Security News, Weekly update
Weekly Update 480
Well, I now have the answer to how Snapchat does age verification for under-16s: they give an underage kid the ability to change their date of birth, then do a facial scan to verify. The facial scan (a third party tells me…) allows someone well under 16 to pass it easily. So, is that control…
Global Security News, Weekly update
Weekly Update 479
I gave up on the IoT water meter reader. Being technical and thinking you can solve everything with technology is both a blessing and a curse; dogged persistence has given me the life I have today, but it has also burned serious amounts of time because I never want to let a problem go unsolved.…
Global Security News, Weekly update
Weekly Update 478
This week, it was an absolute privilege to be at Europol in The Hague, speaking about cyber offenders and at the InterCOP conference and spending time with some of the folks involved in the Operation Endgame actions. The latter in particular gave me a new sense of just how much coordination is involved in this…
Global Security News, Weekly update
Weekly Update 477
What. A. Week. It wasn’t just the preceding weeks of technical pain as we tried to work out how to get this data loaded, it was all the subsequent queries we had to deal with too. Some of them are totally understandable, whilst others just resulted in endless facepalms 🤦♂️ But we got there in…
Europe, Global Security News, Weekly update
Weekly Update 476
The 2 billion email address stealer log breach I talk about this week is almost ready to go at the time of writing. It’s been massively time-consuming, massively expensive (we turned the cloud up to 11) and enormously frustrating. I’ve written about why in the draft blog post, but once you get to the point…
Global Security News, Weekly update
Weekly Update 475
It was the Synthient threat data that ate most of my time this week, and it continues to do so now, the weekend after recording this video. Data like this is equal parts enormously damaging to victims and frustratingly noisy to process. I have to be confident enough that it’s new enough, legit enough and…
Global Security News, Weekly update
Weekly Update 474
You’re not going to believe this – the criminals that took the Qantas data ignored the injunction 😮 I know, I know, we’re all a bit stunned that making crime illegal hasn’t appeared to stop it, but here we are. Just before the time of writing, I was contacted by someone who received a breach…
Global Security News, Weekly update
Weekly Update 473
This week’s video was recorded on Friday morning Aussie time, and as promised, hackers dumped data the following day. Listening back to parts of the video as I write this on a Sunday morning, pretty much what was predicted happened: data was dumped, it included Qantas, and the injunction did nothing to stop it. I…
Global Security News, Weekly update
Weekly Update 472
This probably comes through pretty strongly in this week’s video, but I love the vibe at CERN. It’s a place so focused on the common good of science that all the other cultural attributes that often put people at odds these days fade into the distance. That hit me more than it did on my…
Global Security News, Weekly update
Weekly Update 471
I’m so happy to finally be getting those HIBP demos out! The first couple are simple, but as I say in this week’s vid, it’s the simple questions we’re still dealing with. As if to taunt me (or prove my point), we got this ticket just a couple of hours ago: I’m looking at 10-12k…
Global Security News, Weekly update
Weekly Update 470
Imagine jumping on board a class action after your precious datas have been breached, then sticking through it all the way until a settlement is reached. Then, finally, after a long and arduous battle, cashing in and getting… $1. Well, kinda $1, the ParkMobile class action granted up to $1 for successful claimants. But wait…
Global Security News, Weekly update
Weekly Update 469
So I had this idea around training a text-to-speech engine with my voice, then using that to speak over the Sonos at home to announce AI-driven events, such as people ringing the doorbell. A few hours’ worth of video from these weekly updates fed into ElevenLabs and wammo! Here you go: Oh yeah! Now *this*…
Asia Pacific, Global Security News, Weekly update
Weekly Update 468
I only just realised, as I prepared this accompanying blog post, that I didn’t talk about one of the points in the overview: food. One of my fondest memories as a child living in Singapore and now as an adult visiting there is the food. It’s one of those rare places where the food at…
Asia Pacific, Global Security News, Weekly update
Weekly Update 467
Using AI to analyse photos and send alerts if I’ve forgotten to take the bins out isn’t going to revolutionise my life, no more so than using it to describe who’s at the mailbox when a letter arrives and at the front door when they buzz. But that’s really not the point; it’s by playing…
Global Security News, Weekly update
Weekly Update 466
I’m fascinated by the unwillingness of organisations to name the “third party” to which they’ve attributed a breach. The initial reporting on the Allianz Life incident from last month makes no mention whatsoever of Salesforce, nor does any other statement I can find from them. And that’s very often the way with many other incidents…
Global Security News, Weekly update
Weekly Update 465
How much tech stuff do I have sitting there in progress, literally just within arm’s reach? I kick off this week’s video going through it, and it’s kinda nuts. Doing runeos and house build doesn’t help, but it means there’s just a constant distraction of “things” commanding my attention. I couldn’t even go through writing…
Global Security News, Weekly update
Weekly Update 464
I think the most amusing comment I had during this live stream was one to the effect of expecting me to have all my tech things neat and ordered. As I look around me now, there are Shellys with cables hanging off them all over my desk, the keyboard I’m typing on has become very…
Global Security News, Weekly update
Weekly Update 463
I’ve listened to a few industry podcasts discussing the Tea app breach since recording, and the thing that really struck me was the lack of discussion around the privacy implications of the service before the breach. Here was a tool where people were non-consensually uploading photos of others and leaving fairly intimate commentary about them.…
Global Security News, Weekly update
Weekly Update 462
This will be the title of the blog post: “Court Injunctions are the Thoughts and Prayers of Data Breach Response”. It’s got a nice ring to it, and it resonates so much with the response to other disasters where the term is offered as a platitude that has absolutely no practical benefit at all. You…
Global Security News, Weekly update
Weekly Update 461
The Stripe situation is frustrating: by mandating an email address on all invoices, we’re providing a channel that sends customer queries directly through to us rather than via our support portal, which already has the answers many people are raising tickets for. It’s frustrating because it slows our customers down (they need to wait for…
Global Security News, Weekly update
Weekly Update 460
This week’s update is the last remote one for a while as we wind up more than a month of travel. I’m pushing this out just before we jump on the Qantas plane home… right after they’ve advised just how much of my data was impacted by their breach. That got me thinking in this…
Global Security News, Weekly update
Weekly Update 459
New week, different end of the world! After a fleeting stop at home, we’re in Japan for a proper holiday (yet somehow I’m still here writing this…) with the first stop in Tokyo. It’s like nowhere else here, and this is now probably my 10th trip to Japan over a period of more than three…
Global Security News, Weekly update
Weekly Update 458
I’m in Austria! Well, I was in Austria, I’m now somewhere over the Aussie desert as I try and end this trip on top of my “to-do” list. The Have I Been Pwned Alpine Grand Tour was a great success with loads of time spent with govs, public meetups and users of this little data…
Global Security News, Weekly update
Weekly Update 457
Firstly, apologies for the annoying clipping in the audio. I use a Rode VideoMic that’s a shotgun style that plugs straight into the iPhone and it’s usually pretty solid. It was also solid when I tested it again now, just recording a video into the phone, so I don’t know if this was connection related…
Europe, Global Security News, Weekly update
Weekly Update 456
It’s time to fly! It’s two months to the day since we came back from the last European trip, again spending the time with some of the agencies and partners we’ve fostered at HIBP over the years. This time, it’s the driving tour I talked about earlier last month, and we have absolutely jam-packed it!…
Global Security News, Weekly update
Weekly Update 455
The bot-fighting is a non-stop battle. In this week’s video, I discuss how we’re tweaking Cloudflare Turnstile and combining more attributes around how bot-like requests are, and… it almost worked. Just as I was preparing to write this intro, I found a small spike of anomalous traffic that, upon further investigation, should have been blocked.…
Global Security News, Weekly update
Weekly Update 454
We’re two weeks in from the launch of the new HIBP, and I’m still recovering. Like literally still recovering from the cold I had last week and the consequent backlog. A major launch like this isn’t just something you fire and forget; instead, it takes weeks of tweaks and refinements to iron out all the…
Global Security News, Weekly update
Weekly Update 454
We’re two weeks in from the launch of the new HIBP, and I’m still recovering. Like literally still recovering from the cold I had last week and the consequent backlog. A major launch like this isn’t just something you fire and forget; instead, it takes weeks of tweaks and refinements to iron out all the…
Global Security News, Weekly update
Weekly Update 454
We’re two weeks in from the launch of the new HIBP, and I’m still recovering. Like literally still recovering from the cold I had last week and the consequent backlog. A major launch like this isn’t just something you fire and forget; instead, it takes weeks of tweaks and refinements to iron out all the…
Global Security News, Weekly update
Weekly Update 453
Well, the last few weeks of insane hours finally caught up with me 🤒 Not badly, but I evidently burned enough midnight oil to leave the immune system somewhat degraded and just after recording this video, I really didn’t feel like doing much at all. Some congestion and sniffles aside, it’s really not that bad,…
Global Security News, Weekly update
Weekly Update 453
Well, the last few weeks of insane hours finally caught up with me 🤒 Not badly, but I evidently burned enough midnight oil to leave the immune system somewhat degraded and just after recording this video, I really didn’t feel like doing much at all. Some congestion and sniffles aside, it’s really not that bad,…
Global Security News, Weekly update
Weekly Update 453
Well, the last few weeks of insane hours finally caught up with me 🤒 Not badly, but I evidently burned enough midnight oil to leave the immune system somewhat degraded and just after recording this video, I really didn’t feel like doing much at all. Some congestion and sniffles aside, it’s really not that bad,…
Global Security News, Weekly update
Weekly Update 452
Funny how excited people can get about something as simple as a sticker. They’re always in hot demand and occupy an increasingly large portion of my luggage as we travel around. Charlotte reckoned it would be the same for other merch too, so, while I’ve been beavering away playing code monkey on the rebranded HIBP…
Europe, Global Security News, Weekly update
Weekly Update 451
The Have I Been Pwned Alpine Grand Tour is upon us! I’ve often joked that work is always either sitting at my desk at home in isolation or on the other side of the world, and so it is with this trip. As we’ve done with recent travel to the US and colder parts of…
Europe, Global Security News, Weekly update
Weekly Update 450
Looking back at this week’s video, it’s the AI discussion that I think about most. More specifically, the view amongst some that any usage of it is bad and every output is “slop”. I’m hearing that much more broadly lately, that AI is both “robbing” creators and producing sub-par results. The latter is certainly true…
Global Security News, Weekly update
Weekly Update 449
Today, I arrived at my PC first thing in the morning to find the UPS dead (battery was cactus) and the PC obviously without power. So, I tracked down a powerboard and some IEC C14 to mains cable adaptors and powered back up. On boot, neither the Bluetooth mouse nor keyboard worked. So, I tracked…
Global Security News, Weekly update
Weekly Update 448
I’m a few days late this week, finally back from a month of (almost) non-stop travel with the last bit being completely devoid of an internet connection 😲 And now, the real hard work kicks in as we count down the next 25 days before launching the full HIBP rebrand. I’m adamant we’re going to…
Global Security News, Weekly update
Weekly Update 447
I’m home! Well, for a day, then it’s off to the other side of the country (which I just flew over last night on the way back from Dublin 🤦♂️) for an event at the Microsoft Accelerator in Perth on Monday. Such is the path we’ve taken, but it does provide some awesome opportunities to…
Global Security News, Weekly update
Weekly Update 446
After an unusually long day of travelling from Iceland, we’ve finally made it to the land of Guinness, Leprechauns, and a tax haven for tech companies. This week, there are a few more lessons from the successful phish against me the previous week, and in happier news, there is some really solid progress on the…
Global Security News, Weekly update
Weekly Update 445
Well, this certainly isn’t what I expected to be talking about this week! But I think the fact it was someone most people didn’t expect to be on the receiving end of an attack like this makes it all the more consumable. I saw a lot of “if it can happen to Troy, it can…
Global IT News, Global Security News, Weekly update
Weekly Update 444
It’s time to fly! 🇬🇧 🇮🇸 🇮🇪 That’s two new flags (or if you’re on Windows and can’t see flag emojis, that’s two new ISO codes) I’ll be adding to my “places I’ve been list” as we start the journey by jetting out to London right after I publish this blog. If you’re in the…
Global Security News, Weekly update
Weekly Update 443
What an awesome response to the new brand! I’m so, so happy with all the feedback, and I’ve gotta be honest, I was nervous about how it would be received. The only negative theme that came through at all was our use of Sticker Mule, which apparently is akin to being a Tesla owner. Political…
Global Security News, Weekly update
Weekly Update 442
We survived the cyclone! That was a seriously weird week with lots of build-up to an event that last occurred before I was born. It’d been 50 years since a cyclone came this far south, and the media was full of alarming predictions of destruction. In the end, we maxed out at 52kts just after…
Global IT News, Global Security News, Weekly update
Weekly Update 441
Processing data breaches (especially big ones), can be extremely laborious. And, of course, everyone commenting on them is an expert, so there’s a heap of opinions out there. And so it was with the latest stealer logs, a corpus of data that took the better part of a month to process. And then I made…
Global Security News, Weekly update
Weekly Update 440
Wait – it’s Tuesday already?! When you listen to this week’s (ok, last week’s) video, you’ll probably get the sense I was a bit overloaded. Yeah, so that didn’t stop, and the stealer log processing and new feature building just absolutely swamped me. Plus, I spent from then until now in Sydney at various meetings…
Global Security News, Weekly update
Weekly Update 439
We’re now eyeball-deep into the HIBP rebrand and UX work, totally overhauling the image of the service as we know it. That said, a guiding principle has been to ensure the new looks is immediately recognisable and over months of work, I think we’ve achieved that. I’m holding off sharing anything until we’re far enough…
Global Security News, Weekly update
Weekly Update 438
I think what’s really scratching an itch for me with the home theatre thing is that it’s this whole geeky world of stuff that I always knew was out there, but I’d just never really understood. For example, I mentioned waveforming in the video, and I’d never even heard of that let alone understood that…
Global Security News, Weekly update
Weekly Update 437
It’s IoT time! We’re embarking on a very major home project (more detail of which is in the video), and some pretty big decisions need to be made about a very simple device: the light switch. I love having just about every light in our connected… when it works. The house has just the right…
Europe, Global Security News, Weekly update
Weekly Update 436
We’re heading back to London! And making a trip to Reykjavik. And Dublin. I talked about us considering this in the video yesterday, and just before publishing this post, we pulled the trigger and booked the tickets. The plan is to pretty much repeat the US and Canada trip we did in September and spend…
Global Security News, Weekly update
Weekly Update 435
If I’m honest, I was in two minds about adding additional stealer logs to HIBP. Even with the new feature to include the domains an email address appears against in the logs, my concern was that I’d get a barrage of “that’s useless information” messages like I normally do when I load stealer logs! Instead,…
Global Security News, Weekly update
Weekly Update 434
This week I’m giving a little teaser as to what’s coming with stealer logs in HIBP and in about 24 hours from the time of writing, you’ll be able to see the whole thing in action. This has been a huge amount of work trawling through vast volumes of data and trying to make it…
Global Security News, Weekly update
Weekly Update 433
It sounds easy – “just verify people’s age before they access the service” – but whether we’re talking about porn in the US or Australia’s incoming social media laws, the reality is way more complex than that. There’s no unified approach across jurisdictions and even within a single country like Australia, the closest we’ve got…
Global Security News, Weekly update
Weekly Update 432
There’s a certain irony to the Bluesky situation where people are pushing back when I include links to X. Now, where have we seen this sort of behaviour before? 🤔 When I’m relying on content that only appears on that platform to add context to a data breach in HIBP and that content is freely…
Global Security News, Weekly update
Weekly Update 431
I fell waaay behind the normal video cadence this week, and I couldn’t care less 😊 I mean c’mon, would you rather be working or sitting here looking at this view after snowboarding through Christmas?! Christmas Day awesomeness in Norway 🇳🇴 Have a great one friends, wherever you are 🧑🎄 pic.twitter.com/F2FtcJYzRC — Troy Hunt (@troyhunt)…
Global Security News, Weekly update
Weekly Update 430
I’m back in Oslo! Writing this the day after recording, it feels like I couldn’t be further from Dubai; the temperature starts with a minus, it’s snowing and there’s not a supercar in sight. Back on business, this week I’m talking about the challenge of loading breaches and managing costs. A breach load immediately takes…
Global Security News, Weekly update
Weekly Update 429
A super quick intro today as I rush off to do the next very Dubai thing: drive a Lambo through the desert to go dirt bike riding before jumping in a Can-Am off-roader and then heading to the kart track for a couple of afternoon sessions. I post lots of pics to my Facebook account,…
Global Security News, Weekly update
Weekly Update 428
I wouldn’t say this is a list of my favourite breaches from this year as that’s a bit of a disingenuous term, but oh boy were there some memorable ones. So many of the incidents I deal with are relatively benign in terms of either the data they expose or the nature of the service,…
Global Security News, Weekly update
Weekly Update 427
I was going to write about how much I’ve enjoyed “tinkering” with the HIBP API, but somehow, that term doesn’t really seem appropriate any more for a service of this scale. On the contrary, we’re putting in huge amounts of effort to get this thing fast, stable, and sustainable. We could do the first two…
Global Security News, Weekly update
Weekly Update 426
I have absolutely no problem at all talking about the code I’ve screwed up. Perhaps that’s partly because after 3 decades of writing software (and doing some meaningful stuff along the way), I’m not particularly concerned about showing my weaknesses. And this week, I screwed up a bunch of stuff; database queries that weren’t resilient…
Global Security News, Weekly update
Weekly Update 425
This was a much longer than usual update, largely due to the amount of time spent discussing the Earth 2 incident. As I said in the video (many times!), the amount of attention this has garnered from both Earth 2 users and the company itself is incommensurate with the impact of the incident itself. It’s…
Global Security News, Weekly update
Weekly Update 424
I have really clear memories of listening to the Stack Overflow podcast in the late 2000’s and hearing Jeff and Joel talk about the various challenges they were facing and the things they did to overcome them. I just suddenly thought of that when realising how long this week’s video went for with no real…
Global Security News, Weekly update
Weekly Update 423
Firstly, my apologies for the minute and a bit of echo at the start of this video, OBS had somehow magically decided to start recording both the primary mic and the one built into my camera. Easy fix, moving on… During the livestream, I was perplexed as to why the HIBP DB was suddenly maxing…
Global Security News, Weekly update
Weekly Update 422
Apparently, Stefan and I trying to work stuff out in real time about how to build more efficient features in HIBP is entertaining watching! If I was to guess, I think it’s just seeing people work through the logic of how things work and how we might be able to approach things differently, and doing…
Global Security News, Weekly update
Weekly Update 421
It wasn’t easy talking about the Muah.AI data breach. It’s not just the rampant child sexual abuse material throughout the system (or at least requests for the AI to generate images of it), it’s the reactions of people to it. The tweets justifying it on the basis of there being noo “actual” abuse, the characterisation…
Global Security News, Weekly update
Weekly Update 420
Ok, the scenery here is amazing, but the real story is data breach victim notification. Charlotte and I wanted to do this one together today and chat about some of the things we’d been hearing from government and law enforcement on our travels, and the victim notification angle featured heavily. She reminded me of the…
Global Security News, Weekly update
Weekly Update 419
It’s not a green screen! It’s just a weird a weird hotel room in Pittsburgh, but it did make for a cool backdrop for this week’s video. We were there visiting our FBI friends after coming from Washington DC and a visit to CISA, the “America’s Cyber Defence Agency”. This week, I’m talking about those…
