/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Have I Been Pwned goes open source, starting with the Pwned Password code; FBI to begin sharing compromised passwords discovered in investigations with the site

Want to find out if someone's stolen your user IDs and passwords?  Then you can use “Have I Been Pwned,” and now the code behind it is being open sourced.

ZDNet Steven J. Vaughan-Nichols

Context & Ripple Effects

Have I Been Pwned had already become infrastructure for password-risk checks: its Pwned Passwords API was adopted by 1Password, and breach search later reached 1Password Watchtower and Firefox Monitor. Troy Hunt had also signaled an intention to open-source the code base.

This report joins that software-opening step to a new public-sector data channel, with the FBI set to contribute passwords uncovered in investigations. The model was subsequently echoed when the UK's National Crime Agency shared compromised passwords with the service.

First-order effects

  • Developers can inspect and reuse the Pwned Passwords code, extending a service that password managers and browser-facing tools already use for exposure checks.
  • Have I Been Pwned gains a new planned source of compromised-password data from FBI investigations, while the FBI gains a route for making that intelligence useful to credential-defense tools.

Second-order effects

  • 1Password Watchtower and Firefox Monitor become more dependent on Have I Been Pwned as a shared upstream layer for password-exposure alerts rather than maintaining separate breach-intelligence pipelines.
  • The FBI arrangement establishes an operational precedent for law-enforcement contributions that the National Crime Agency later followed, widening the potential contributor base beyond breach disclosures and public dumps.

Third-order effects

  • If agency contributions and open code continue together, credential defense shifts toward shared, inspectable infrastructure linking investigators, security-product providers, and end users rather than isolated breach-notification services.

The trend: Credential-security services are becoming ecosystem infrastructure, combining open implementations with shared breach intelligence from public agencies and consumer-security products.

Discussion

  • @troyhunt Troy Hunt on x
    I'm very happy to announce that @haveibeenpwned's Pwned Passwords is now open source under the @dotnetfdn. Now we've got some work to do: building an ingestion pipeline for new passwords provided by the @FBI on an ongoing basis. This is super cool 😎 https://www.troyhunt.com/...
  • @epro Emil Protalinski on x
    Huge props to @troyhunt here. Yet another example of how one person's work can make a significant difference in cybersecurity. https://twitter.com/...
  • @kalisurfer Sean Scott on x
    If banks and Fintech want to have trust front and center why not leverage services like this one to tell customers whether their passwords are compromised https://twitter.com/...