ArticleslgStudy

science

Have I Been Pwned?

Have I Been Pwned? is a science topic covered in the lgStudy science library. This page brings together a partial reference excerpt, illustrations, worked examples, real-world applications and a short study plan, so you can understand Have I Been Pwned? rather than just read about it. In short: Have I Been Pwned? (HIBP) is a website that allows Internet users to check whether their email address or password has been compromised by data breaches.

Have I Been Pwned? — main illustration
Have I Been Pwned? — illustration

Key takeaways

  • Have I Been Pwned? belongs to science; place it in that map before memorising details.
  • Learn the definition first, then one example that makes the definition concrete.
  • Connect Have I Been Pwned? to a quantity you can measure, compute or draw — that is where exam questions come from.
  • Reproduce the core statement of Have I Been Pwned? from memory before moving on to harder problems.

Reference excerpt

Have I Been Pwned? (HIBP) is a website that allows Internet users to check whether their email address or password has been compromised by data breaches. The site has been widely touted as a valuable resource for Internet users wishing to protect their own security and privacy. Have I Been Pwned? was created by security expert Troy Hunt on 4 December 2013. As of June 2019, Have I Been Pwned? averages around 160,000 daily visitors, the site has nearly three million active email subscribers and contains records of almost eight billion accounts.

Features The primary function of Have I Been Pwned? since it was launched is to provide the general public with a means to check if their private information has been leaked or compromised. The service collects and analyzes hundreds of database dumps and pastes containing information about billions of leaked accounts, and allows users to search for their own information by entering their username or email address. Users can also sign up to be notified if their email address appears in future dumps.

Usage of Dump Monitor In September 2014, Hunt added functionality that enabled new data breaches to be automatically added to HIBP's database. The new feature used Dump Monitor, a Twitter bot which detects and broadcasts likely password dumps found on pastebin pastes, to automatically add new potential breaches in real-time. Data breaches often show up on pastebins before they are widely reported on; thus, monitoring this source allows consumers to be notified sooner if they've been compromised.

Pwned passwords In August 2017, Hunt made public 306 million passwords which could be accessed via a web search or downloadable in bulk. In February 2018, British computer scientist Junade Ali created a communication protocol (using k-anonymity and cryptographic hashing) to anonymously verify if a password was leaked without fully disclosing the searched password. This protocol was implemented as a public API in Hunt's service and is now consumed by multiple websites and services including password managers and browser extensions. This approach was later replicated by Google's Password Checkup feature. Ali worked with academics at Cornell University to formally analyse the protocol to identify limitations and develop two new versions of this protocol known as Frequency Size Bucketization and Identifier Based Bucketization. In March 2020, cryptographic padding was added to this protocol.

History

Launch

In late 2013, web security expert Troy Hunt was analyzing data breaches for trends and patterns. He realized breaches could greatly impact users who might not even be aware their data was compromised, and as a result, began developing HIBP. "Probably the main catalyst was Adobe," said Hunt of his motivation for starting the site, referring to the Adobe Systems security breach that affected 153 million accounts in October 2013. Hunt launched Have I Been Pwned? on 4 December 2013 with an announcement on his blog. At that time, the site had just five data breaches indexed: Adobe Systems, Stratfor, Gawker, Yahoo! Voices, and Sony Pictures. However, the site now had the functionality to easily add future breaches as soon as they were made public. Hunt wrote:

Now that I have a platform on which to build I'll be able to rapidly integrate future breaches and make them quickly searchable by people who may have been impacted. It's a bit of an unfair game at the moment – attackers and others wishing to use data breaches for malicious purposes can very quickly obtain and analyse the data but your average consumer has no feasible way of pulling gigabytes of gzipped accounts from a torrent and discovering whether they've been compromised or not.

Unsuccessful effort to sell Midway through June 2019, Hunt announced plans to sell Have I Been Pwned? to a yet to be determined organisation. In his blog, he outlined his wishes to reduce personal stress and expand the site beyond what he was able to accomplish himself. As of the release of the blog post, he was working with KPMG to find companies he deemed suitable which were interested in the acquisition. However, in March 2020, he announced on his blog that HIBP would remain independent for the foreseeable future.

Open-sourcing On August 7, 2020, Hunt announced on his blog his intention to open-source the Have I Been Pwned? codebase. Hunt started publishing some code on May 28, 2021.

Branding The name "Have I Been Pwned?" uses the hacker jargon term "pwn", which means "to gain unauthorized access to or compromise" a computer system. HIBP's logo includes the text ';--, which is a common SQL injection attack string. A hacker trying to take control of a website's database might use such an attack string to manipulate a website into running malicious code. Injection attacks are one of the most common vectors by which a database breach can occur; they are the top most common web application vulnerability on the OWASP Top 10 list.

Data breaches Since its launch, the primary development focus of HIBP has been to add new data breaches as quickly as possible after they are leaked to the public.

Ashley Madison In July 2015, online dating service Ashley Madison, known for encouraging users to have extramarital affairs, suffered a data breach, and the identities of more than 30 million users of the service were leaked to the public. The data breach received wide media coverage, presumably due to the large number of impacted users and the perceived shame of having an affair. According to Hunt, the breach's publicity resulted in a 57,000% increase in traffic to HIBP. Following this breach, Hunt added functionality to HIBP by which breaches considered "sensitive" would not be publicly searchable, and would only be revealed to subscribers of the email notification system. This functionality was enabled for the Ashley Madison data, as well as for data from other potentially scandalous sites, such as Adult FriendFinder.

… excerpt ends here. Continue reading the full article.

Illustrations

Have I Been Pwned? illustration
Have I Been Pwned? illustration
Have I Been Pwned?: Troy Hunt, the creator of Have I Been Pwned?
Troy Hunt, the creator of Have I Been Pwned?

Worked examples

Example 1 — a first encounter with Have I Been Pwned?

Start with the simplest possible case. Write down what Have I Been Pwned? claims or describes in one sentence, then invent the smallest concrete situation in which that sentence is true. In science, the smallest case is usually a single object, a single equation or a single measurement. Check that every symbol or term in your sentence has a meaning in that case.

Example 2 — changing one variable

Take the situation from Example 1 and change exactly one quantity: double it, halve it, or set it to zero. Predict what should happen to Have I Been Pwned? before you calculate. Comparing your prediction with the result is the fastest way to find out whether you understand the idea or only the words.

Example 3 — an exam-style question

Typical questions about Have I Been Pwned? ask you to (a) state it precisely, (b) apply it to given data, and (c) explain a limitation. Practise writing all three answers in under five minutes; the third part is what separates a full-mark answer from an average one.

Applications of Have I Been Pwned?

In research
Have I Been Pwned? appears in science research whenever the underlying quantities have to be modelled precisely. Papers usually cite it as a starting assumption and then explore where it breaks down.
In technology and industry
Engineering practice reuses Have I Been Pwned? in design rules, simulations and safety margins. Knowing the idea lets you read a specification sheet and understand why the numbers look the way they do.
In the classroom
Have I Been Pwned? is common in secondary-school and first-year university syllabi. It links to neighbouring topics 2013 establishments in Australia, Australian websites, Database security, so understanding it makes those chapters shorter.
In everyday life
Look for Have I Been Pwned? outside the textbook — in sport, cooking, traffic, electronics or the sky above you. An example you found yourself is remembered far longer than one you were given.
Ask Teacher Smith questions about this articleOpens your AI tutor with a question about “Have I Been Pwned?” →

Affiliate

Preply — study more efficiently by working with a personal tutor. 50% off.

How to study Have I Been Pwned? in 20 minutes

  1. Read the reference excerpt below once, without taking notes.
  2. Close the page and write down what Have I Been Pwned? means in your own words.
  3. Compare your version with the excerpt and mark what you missed.
  4. Work through the three examples above with pen and paper.
  5. Explain Have I Been Pwned? out loud to somebody else — or to Teacher Smith in the lgStudy chat.

Frequently asked questions

What is Have I Been Pwned? in simple terms?

Have I Been Pwned? (HIBP) is a website that allows Internet users to check whether their email address or password has been compromised by data breaches.

Why does Have I Been Pwned? matter?

Because it connects several science ideas at once: it gives you a definition you can apply, a quantity you can calculate, and a way to check whether a result is plausible.

How should I study Have I Been Pwned??

Read the excerpt, restate it from memory, then work through the examples and applications listed on this page. The five-step study plan above takes about twenty minutes.

What does this page cover?

It gives you a compact reference excerpt plus original lgStudy explanations, examples, applications and study material on Have I Been Pwned?.

Tags

  • 2013 establishments in Australia
  • Australian websites
  • Database security
  • English-language websites
  • Internet security
  • Technology websites

Keep exploring