Have I Been Pwned is now open source

Hacker
(Image credit: Shutterstock)

The code powering the popular Have I Been Pwned? (HIBP) website that allows users to check whether any login information has been compromised, is now available under an open source license to everyone.

Created and managed by cybersecurity expert Troy Hunt, HIBP has gained millions of fans over the last seven years. In 2020 Hunt tried to unsuccessfully sell the project when he realized that it could no longer be managed by a single individual. 

"The philosophy of HIBP has always been to support the community, now I want the community to help support HIBP," Hunt wrote last year when he initiated the process to open source the code behind HIBP. 

TechRadar needs you!

We're looking at how our readers use VPN for a forthcoming in-depth report. We'd love to hear your thoughts in the survey below. It won't take more than 60 seconds of your time.

>> Click here to start the survey in a new window<<

That process has now been completed and all the HIBP code, which is written in .NET and runs on Microsoft Azure, is now available on GitHub under the BSD 3-clause license.

Collaboration with the FBI

HIBP pools data about the leaks from security breaches around the world, and allows users to search for their own information by entering their username or email address. Users can also sign up with HIBP to be notified if their email address leaked in a security breach in the future. 

The service is notable for being the first to implement a cryptographic hashing communications protocol that allows it to verify if a password was leaked without fully disclosing the searched password. 

The open source protocol is now being used by virtually all password managers.

As he announced the completion of the open source process, Troy also shared that the FBI has decided to feed all compromised passwords discovered in the course of their investigations into HIBP as well.

"We are excited to be partnering with HIBP on this important project to protect victims of online credential theft. It is another example of how important public/private partnerships are in the fight against cybercrime," said FBI's Assistant Director, Cyber Division, Bryan A. Vorndran.

Via ZDNet

Mayank Sharma

With almost two decades of writing and reporting on Linux, Mayank Sharma would like everyone to think he’s TechRadar Pro’s expert on the topic. Of course, he’s just as interested in other computing topics, particularly cybersecurity, cloud, containers, and coding.

Read more
HPE
HPE investigating claims that hacker breached developer environments, source code
Dark web scanning on a laptop
Hostinger integrates dark web scanning into hPanel
Man screaming at computer with TechRadar data privacy week logo next to it.
I almost lost my entire online identity – until one tool made all the difference
SearchGPT OpenAI
Hackers offer 20 million OpenAI credentials for sale, but it says there's no evidence of a breach
A digital themed isometric showing a neon padlock in the foreground, and a technological diagram of a processor logic board in the background.
A top online gift card store may have exposed private data on hundreds of thousands of users
hacker.jpeg
Thousands of GitHub repositories exposed via Microsoft Copilot
Latest in Security
Lock on Laptop Screen
Medusa ransomware is able to disable anti-malware tools, so be on your guard
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Coinbase targeted after recent Github attacks
hacker.jpeg
Key trusted Microsoft platform exploited to enable malware, experts warn
IBM office logo
IBM to provide platform for flagship cyber skills programme for girls
Oracle
Oracle denies data breach after hacker claims to hold six million records
Hacker silhouette working on a laptop with North Korean flag on the background
North Korea unveils new military unit targeting AI attacks
Latest in News
Cassian Andor looking nervously over his shoulder in Andor season 2
New Andor season 2 trailer has got Star Wars fans asking the same question – and it includes an ominous call back to Rogue One's official teaser
23andMe
23andMe is bankrupt and about to sell your DNA, here's how to stop that from happening
A phone showing a ChatGPT app error message
ChatGPT was down for many – here's what happened
AirPods Max with USB-C in every color
Apple's AirPods Max with USB-C will get lossless audio in April, but you'll need to go wired
A woman sitting in a chair looking at a Windows 11 laptop
It looks like Microsoft might have thought better about banishing Copilot AI shortcut from Windows 11
Lock on Laptop Screen
Medusa ransomware is able to disable anti-malware tools, so be on your guard