korrents

Troy Hunt

@troy-hunt · 7 positions · 0 changes of mind

Security researcher who runs Have I Been Pwned, the service that tells people which breaches their email address turned up in. He writes at troyhunt.com about breaches, passwords and what actually goes wrong, including when it goes wrong to him.

Troy Hunt did not write this page.

We collected these quotes from things they published elsewhere, and every quote links to where it was said. They have no account here and have not endorsed this site. Quotes are word for word; the short line under each one is our own restatement, not their wording. Their own site. Is this you? Claim it or ask us to remove it. Or tell us what is wrong here.

  1. This was obviously highly automated and designed to immediately export the list before the victim could take preventative measures.

    A Sneaky Phish Just Grabbed my Mailchimp Mailing Listtroyhunt.com 1st of 2 in this piece

  2. When I have conversations with breached companies, my messaging is crystal clear: be transparent and expeditious in your reporting of the incident and prioritise communicating with your customers.

    A Sneaky Phish Just Grabbed my Mailchimp Mailing Listtroyhunt.com 2nd of 2 in this piece

  3. 7 years earlier
  4. So that's precisely what I've done - intercepted my own traffic passed over an insecure connection and put together a string of demos in a 24-minute video explaining why HTTPS is necessary on a static website.

    Here's Why Your Static Website Needs HTTPStroyhunt.com

  5. 12 months earlier
  6. In some cases, this has led to once-held "truths" about how we create and manage accounts to be totally flipped on their head, yet we still see modern organisations applying the patterns of yesterday to the threats of today.

    Passwords Evolved: Authentication Guidance for the Modern Eratroyhunt.com 1st of 4 in this piece

  7. password managers don't have to be perfect, they just have to be better than not having one.

    Passwords Evolved: Authentication Guidance for the Modern Eratroyhunt.com 2nd of 4 in this piece

    management

  8. When a website blocks the pasting of passwords in an attempt to improve security, they force some users to weaken their passwords to the point where they're dumbed down to easily typed versions.

    Passwords Evolved: Authentication Guidance for the Modern Eratroyhunt.com 3rd of 4 in this piece

  9. If you're working in an environment that mandates regular password changes, you're very likely doing the same thing because it's an easy human control to deal with a technology requirement that's seen as an impediment.

    Passwords Evolved: Authentication Guidance for the Modern Eratroyhunt.com 4th of 4 in this piece