{"id":262049,"date":"2021-05-28T20:43:52","date_gmt":"2021-05-28T17:43:52","guid":{"rendered":"https:\/\/en.buradabiliyorum.com\/have-i-been-pwneds-password-program-is-now-open-source-accepting-data-from-fbi-review-geek\/"},"modified":"2021-05-28T20:43:52","modified_gmt":"2021-05-28T17:43:52","slug":"have-i-been-pwneds-password-program-is-now-open-source-accepting-data-from-fbi-review-geek","status":"publish","type":"post","link":"https:\/\/buradabiliyorum.com\/en\/have-i-been-pwneds-password-program-is-now-open-source-accepting-data-from-fbi-review-geek\/","title":{"rendered":"#Have I Been Pwned\u2019s Password Program Is Now Open Source, Accepting Data from FBI \u2013 Review Geek"},"content":{"rendered":"<p><strong>&#8220;#Have I Been Pwned\u2019s Password Program Is Now Open Source, Accepting Data from FBI \u2013 Review Geek&#8221;<\/strong><\/p>\n<div id=\"article-content-area\">\n<figure style=\"width: 1920px\" class=\"wp-caption alignnone\"><img loading=\"lazy\" decoding=\"async\" class=\"type:primaryImage wp-image-85605 size-full\" src=\"https:\/\/www.reviewgeek.com\/p\/uploads\/2021\/05\/09d913eb.png?width=1200\" alt=\"\" width=\"1920\" height=\"1080\" data-crediturl=\"https:\/\/haveibeenpwned.com\/\" data-credittext=\"Have I Been Pwned\" onload=\"pagespeed.lazyLoadImages.loadIfVisibleAndMaybeBeacon(this);\" onerror=\"this.onerror=null;pagespeed.lazyLoadImages.loadIfVisibleAndMaybeBeacon(this);\"\/><figcaption class=\"wp-caption-text\"><span class=\"type:primaryImage imagecredit\"><a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/haveibeenpwned.com\/\">Have I Been Pwned<\/a><\/span><\/figcaption><\/figure>\n<p>Nearly a year ago, the data breach tracking platform <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/haveibeenpwned.com\/\">Have I Been Pwned<\/a> (HIBP) announced plans to become an open source project. The first step in that transition is now complete\u2014HIBP\u2019s Pwned Passwords code is open source and available on <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/github.com\/HaveIBeenPwned\">GitHub<\/a>. The change provides transparency for HIBP, and oddly enough, opens the door to contributions from the FBI.<\/p>\n<p>Have I Been Pwned keeps track of data breaches and collects stolen data, allowing people to check if their email addresses or passwords have been compromised. Now that HIBP is open-sourcing its Pwned Passwords code, it can accept contributions from the FBI and other organizations that may have insight into data breaches and cybercriminal activity.<\/p>\n<p>In other words, the FBI isn\u2019t meddling with HIBP\u2019s code. It\u2019s just giving data to HIBP in the form of secure SHA-1 and NTLM hash pairs (not plaintext). Bryan A. Vorndran, Assistant Director of the Bureau\u2019s Cyber Division, states that the FBI is \u201cexcited to be partnering with HIBP on this important project to protect victims of online credential theft.\u201d<\/p>\n<blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\">I\u2019m very h<a href=\"https:\/\/buradabiliyorum.com\/en\/category\/download-scripts-themes-apps\/\" data-internallinksmanager029f6b8e52c=\"9\" title=\"Download Scripts &amp; Themes &amp; Apps\" target=\"_blank\" rel=\"noopener\">app<\/a>y to announce that <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/twitter.com\/haveibeenpwned?ref_src=twsrc%5Etfw\">@haveibeenpwned<\/a>\u2019s Pwned Passwords is now open source under the <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/twitter.com\/dotnetfdn?ref_src=twsrc%5Etfw\">@dotnetfdn<\/a>. Now we\u2019ve got some work to do: building an ingestion pipeline for new passwords provided by the <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/twitter.com\/FBI?ref_src=twsrc%5Etfw\">@FBI<\/a> on an ongoing basis. This is super cool \ud83d\ude0e <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/t.co\/iM17zemmwE\">https:\/\/t.co\/iM17zemmwE<\/a><\/p>\n<p>\u2014 Troy Hunt (@troyhunt) <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/twitter.com\/troyhunt\/status\/1397990619985838081?ref_src=twsrc%5Etfw\">May 27, 2021<\/a><\/p>\n<\/blockquote>\n<p>But why start with the Pwned Passwords code? According to HIBP founder Troy Hunt, open-sourcing Pwned Passwords was just the easiest place to start. Pwned Passwords is basically independent from the rest of HIBP with its own domain, CloudFlare account, and Azure services. Plus, it\u2019s non-commercial, and its data is already available to the public in downloadable hash sets.<\/p>\n<p>Hunt hopes that open-sourcing Pwned Passwords will provide greater transparency for the HIBP service and allow people to wrap their own Pwned Passwords tools. It\u2019s a big change from 2019, when Hunt considered selling HIBP.<\/p>\n<p>You can find the Pwned Passwords code <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/github.com\/HaveIBeenPwned\">on GitHub<\/a> licensed under the <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/opensource.org\/licenses\/BSD-3-Clause\">BSD-3 Clause<\/a>. The open-sourcing process is still ongoing, and Hunt is asking people in the open source community to help HIBP develop an ingestion pipeline for contributors like the FBI.<\/p>\n<p><small>Source: Have I Been Pwned via <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/www.zdnet.com\/article\/have-i-been-pwned-goes-open-source\/\">ZDNet<\/a><\/small>\n<\/div>\n<p><script async src=\"\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<p><script>\nsetTimeout(function(){\n  !function(f,b,e,v,n,t,s)\n  {if(f.fbq)return;n=f.fbq=function(){n.callMethod?\n  n.callMethod.apply(n,arguments):n.queue.push(arguments)};\n  if(!f._fbq)f._fbq=n;n.push=n;n.loaded=!0;n.version='2.0';\n  n.queue=[];t=b.createElement(e);t.async=!0;\n  t.src=v;s=b.getElementsByTagName(e)[0];\n  s.parentNode.insertBefore(t,s)}(window, document,'script',\n  'https:\/\/connect.facebook.net\/en_US\/fbevents.js');\n  fbq('init', '1137093656460433');\n  fbq('track', 'PageView');\n  },3000);\n<\/script><\/p>\n<blockquote><p><strong><span style=\"color: #ff6600;\">If you liked the article, do not forget to share it with your friends. Follow us on\u00a0<span style=\"color: #ff0000;\"><a style=\"color: #ff0000;\" href=\"https:\/\/news.google.com\/publications\/CAAqBwgKMLG0nwswvr63Aw\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">Google News<\/a><\/span>\u00a0too, click on the star and choose us from your favorites.<\/span><\/strong><\/p><\/blockquote>\n<blockquote>\n<p style=\"text-align: center;\">For forums sites go to <span style=\"color: #ff9900;\"><a style=\"color: #ff9900;\" href=\"https:\/\/forum.buradabiliyorum.com\/\" target=\"_blank\" rel=\"noopener\">Forum.BuradaBiliyorum.Com<\/a><\/span><\/strong>\n<\/p><\/blockquote>\n<blockquote>\n<p style=\"text-align: center;\"><strong>If you want to read more like this article, you can visit our <span style=\"color: #ff9900;\"><a style=\"color: #ff9900;\" href=\"https:\/\/en.buradabiliyorum.com\/technology\/\" target=\"_blank\" rel=\"noopener\">Technology category.<\/a><\/span><\/strong><\/p>\n<\/blockquote>\n<p><span style=\"color: black;\"><a style=\"color: #ff9900;\" href=\"https:\/\/www.reviewgeek.com\/85602\/have-i-been-pwneds-password-program-is-now-open-source-accepting-data-from-fbi\/\" target=\"_blank\" rel=\"noopener\">Source<\/a><\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>&#8220;#Have I Been Pwned\u2019s Password Program Is Now Open Source, Accepting Data from FBI \u2013 Review Geek&#8221; Have I Been Pwned Nearly a year ago, the data breach tracking platform Have I Been Pwned (HIBP) announced plans to become an open source project. The first step in that transition is now complete\u2014HIBP\u2019s Pwned Passwords code&#8230;<\/p>\n","protected":false},"author":1,"featured_media":262050,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/www.reviewgeek.com\/p\/uploads\/2021\/05\/09d913eb.png","fifu_image_alt":"","footnotes":""},"categories":[18],"tags":[],"class_list":["post-262049","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-technology"],"_links":{"self":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts\/262049","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/comments?post=262049"}],"version-history":[{"count":0,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts\/262049\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/media\/262050"}],"wp:attachment":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/media?parent=262049"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/categories?post=262049"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/tags?post=262049"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}