Have I Been S0ld? Troy Hunt's security website is up for acquisition
Troy Hunt, inventor and operator of the popular security website Have I Been Pwned (HIBP), is putting the service up for sale.
Hunt, a Microsoft Regional Director and MVP for security, created the site in 2013 after Adobe leaked 153 million usernames and weakly encrypted passwords. Users can enter an email address and discover if it is included in the exposed data. You can also enter a password to see if it features in a data breach.
The site was soon extended with data from other breaches and now contains nearly 8 billion records. HIBP publishes an API which gets over 12 million hits a day, most of them checking whether a password is safe to use. Mozilla's Firefox is one of a number of products that integrates with the API to help users choose strong passwords. Commercial subscribers, governments and law enforcement agencies use the service too.
Hunt said in this weeks' announcement that "to date, every line of code, every configuration and every breached record has been handled by me alone. There is no 'HIBP team', there's one guy keeping the whole thing afloat."
He said that maintaining the site has been stressful and has taken him close to burnout. He believes it is time to put the business up for acquisition, which he is doing with KPMG.
The acquisition project is called Project Svalbard, in tribute to a Norwegian effort to store a vault of seeds to protect against future loss. "It sounds like a befitting name, beginning with the obvious analogy of storing a massive quantity of 'units'," Hunt said.
The question everyone will be asking: will the service get worse? Hunt said he will remain part of HIBP and that consumer searches will still be free. The idea is that a bigger organisation will enable him to build out more capabilities.
He also wants to put more effort into changing the behaviour of both individuals and organisations, in respect of their poor security practices.
Hunt has fallen behind, he said, on responsible disclosure – informing organisations that they have been breached. This he called "massively burdensome".
When will it happen? No hurry said, Hunt. "I'm not under any duress (not beyond the high workload, that is) and I've got time to let the acquisition search play out organically and allow it to find the best possible match for the project."
But he does not want to lead a new nonprofit even with sponsorship from other companies, believing that this would increase rather than reduce the stress he is under.
The site performs an excellent, though dispiriting, service. Those of us who have had active email accounts for many years are likely to feature multiple times in the HIBP database. Your correspondent's, for example, is in 20 data breaches including Adobe, Bit.ly, Creative, Disqus, Dropbox, Kickstarter, Last.FM, MySpace and vBulletin, as reported by HIBP.
Sane security today means unique passwords for every site and a password manager, along with other strategies like multi-factor authentication, but take-up is weak as data from services like Microsoft's Office 365 demonstrates.
Industry: Cyber Security
- Information Security Manager- Global Sporting Brand. UK. £100,000
REFCH8265 Identifier Project Information Security Manager- Global Sporting Brand. UK. £100,000 A unique and exclusive opportunity to DCL Search to provide leadership and guidance Information and IT Security practices to one of the most recognised sporting brands in the world. You will be the envy of your colleagues, friends and peers as you take the lead in developing and implementing a security strategy. You must have a blend of knowledge across information security and technical security and be able to build internal and external stakeholder relationships. To coin a well known phrase, you should be a player manager. You don’t need to be currently hands on configuring firewalls, monitoring SIEM alerts, but maybe you have in the past. Ideally you will have come from a technical background as you will be closing be working with technical teams. Skills should include, but not be limited to: Managing / developing to Incident response plans. Information Security Risk Management / compliance. Security awareness Driving remediation plans to address vulnerabilities etc. Hybrid working. Up to £100,000 + benefits.
- Lead Information and Cyber Security Specialist, Financial Services. Exclusive to DCL Search
Consultative approach with experience engaging with internal stakeholders providing advice and guidance across information security policies and standards into projects and programmes. Risk identification / Assessment / Management across people and process. ISO27001. Open mindedness to take on projects and programmes that will involve advising, scoping, refining, improving technical security control relating to best practice. Preferred experience; PCI DSS ISA or consultative experience within security Payment card industry. Information Security / technical security controls within Financial Services. Risk Assessment / management across technical controls. Technical Security background. Experience within secure by design and the technical security controls relating to projects / programmes. iSO27001 Lead Implementer / Auditor. CISA, CISM, CISSP. 2 days a fortnight in London- or more if you want.. Hybrid reworking.
- Cyber Security Associate, Financial Services. Exclusive to DCL Search
Exclusive Cyber Security Associate needed within a forward thinking financial services business head quartered in London. DCL Search have been engaged on an Identifier Project to attract the very best cyber talent to this business. Influence the cyber security capability and direction within the business. Learn new skills working within a collaborative team. Grow as a security professional. ROLE Triaging and troubleshooting security alerts at a level 1 / level 2 capacity. Reviewing security change management requests. Managing and use of security tooling such as; Endpoint management Vulnerability management Patch management CASB Experience with the following tools is desirable. ZOHO Desktop Central (Endpoint Management) Splunk (SIEM) Qualys CASB (Microsoft) Microsoft Azure Varonis DatAdvantage ADAudit Plus Sonicwall, Paloalto, Dark Trace, Cloudflare, Cisco Umbrella, Microsoft defender.
- Senior Cyber Security Engineer, Financial Services. Exclusive to DCL Search
Exclusive Senior Cyber Security Engineer needed within a forward thinking financial services business head quartered in London. DCL Search have been engaged on an Identifier Project to attract the very best cyber talent to this business. Influence the cyber security capability and direction within the business. Learn new skills working within a collaborative team. Grow as a security professional. ROLE Day to day operations, management and scalability of existing cyber security systems Managing of and maturing security tooling such as; SIEM Endpoint Management Firewall Patch Management CASB Vulnerability management. Triaging and troubleshooting security alerts. Improve tooling, reducing false positives. Reviewing, approving, escalating security change management requests. Implementing new cyber security systems. Ideal technical experience · Vulnerability Management: Qualys · Endpoint Management: ZOHO Desktop Central · Forcepoint: CASB, DLP, webs security, email security. · SIEM (Splunk) · Firewalls: Sonicwall, Palo Alto · Endpoint Microsoft Defender · Appreciation of ISO27001, GDPR, PCI, etc 2 days a fortnight in London- or more if you want.. Hybrid reworking.