/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Troy Hunt says he will be open sourcing the Have I Been Pwned code base

Let me just cut straight to it: I'm going to open source the Have I Been Pwned code base.  The decision has been a while coming and it took a failed M&A process to get here, but the code will be turned over to the public …

Troy Hunt

Context & Ripple Effects

Troy Hunt's announcement closes a loop that started when he put Have I Been Pwned up for sale in 2019 to keep pace with the breach archive's growth as its founder and sole employee. That process failed, and a month before this post he had discussed his reluctance to retain breached data and the site's unresolved revenue model — open sourcing is what he chose instead of a corporate owner.

The move builds on an existing pattern of opening the service's core: the Pwned Passwords API had already let password managers like 1Password check logins against leaked credentials, and the code handover extends that trust model from the data to the platform itself.

First-order effects

  • Hunt, as sole employee, shifts from sole custodian to maintainer-in-chief: the code base's survival no longer depends on one person's availability or a successful exit.
  • The failed M&A process becomes public context for the project's governance — buyers walked, and the community inherits the scaling problem instead.

Second-order effects

  • Integrators such as password managers already consuming the Pwned Passwords API gain auditability of the code they depend on, lowering the trust barrier to deeper adoption.
  • A public code base invites external contributors and forks, distributing maintenance load that a single-person operation could not carry as breach volumes grew.

Third-order effects

  • The pattern — critical security infrastructure run by one person, exit attempt fails, code goes open source — points toward community-governed public-interest security services as an alternative to acquisition by platform vendors.
  • If the open-sourcing holds, the boundary between a commercial API service and an open utility blurs: revenue shifts toward hosted data and integrations rather than proprietary software.

The trend: Independently operated breach-notification and credential-checking infrastructure is converging on open source plus public-sector data sharing as the sustainability model when private ownership stalls.

Discussion

  • @troyhunt Troy Hunt on x
    People have been telling me to do this for ages so here it is - I'm open sourcing the code base for @haveibeenpwned. It's non-trivial, but it's the right thing to do. Here's the story: https://www.troyhunt.com/...
  • @rohit11 Rohit Srivastwa on x
    That's big and good news. @troyhunt open sourcing the code base of @haveibeenpwned. https://twitter.com/...