/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Have I Been Pwned goes open source, starting with the Pwned Password code; FBI to begin sharing compromised passwords discovered in investigations with the site

Steven J. Vaughan-Nichols / ZDNet :

ZDNet Steven J. Vaughan-Nichols

Context & Ripple Effects

Have I Been Pwned had already signaled that its code base would be opened, while its password-checking API had become a practical security input for services including 1Password. Opening the Pwned Passwords component turns that earlier open-source commitment into an accessible part of the service’s infrastructure.

The FBI’s planned password sharing adds an institutional source to a database built for downstream security checks. That model was later echoed by the UK National Crime Agency’s contribution of compromised passwords from an investigation, underscoring why the initial FBI arrangement matters beyond a single feed.

First-order effects

  • Have I Been Pwned makes the Pwned Passwords code available for outside inspection and use, giving developers direct visibility into the component behind its compromised-password checks.
  • The FBI will supply passwords found in investigations to Have I Been Pwned, expanding the service’s intake of compromised credentials.

Second-order effects

  • Products using the Pwned Passwords API, including 1Password’s breach-monitoring features, can benefit as Have I Been Pwned incorporates passwords from the FBI feed.
  • The FBI arrangement establishes a reusable handoff between investigators and a public-facing breach-checking service, creating a model other law-enforcement bodies can follow.

Third-order effects

  • If agencies continue contributing investigation-derived credentials, compromised-password defense shifts toward a shared ecosystem in which public authorities, security services, and password managers reinforce the same detection layer.
  • Open-sourcing the checking code makes that ecosystem less dependent on opaque implementation, while Have I Been Pwned remains the coordinating database and distribution point.

The trend: Credential defense is becoming an ecosystem function, combining open security infrastructure with feeds from public investigators and consumer security products.

Discussion

  • @epro Emil Protalinski on x
    Huge props to @troyhunt here. Yet another example of how one person's work can make a significant difference in cybersecurity. https://twitter.com/...
  • @kalisurfer Sean Scott on x
    If banks and Fintech want to have trust front and center why not leverage services like this one to tell customers whether their passwords are compromised https://twitter.com/...
  • @troyhunt Troy Hunt on x
    I'm very happy to announce that @haveibeenpwned's Pwned Passwords is now open source under the @dotnetfdn. Now we've got some work to do: building an ingestion pipeline for new passwords provided by the @FBI on an ongoing basis. This is super cool 😎 https://www.troyhunt.com/...