特洛伊·亨特

RSS: https://troyhunt.com/feed/
Troy Hunt 的安全博客,Have I Been Pwned 创始人,微软 MVP,专注网络安全与隐私保护。

Weekly Update 516: Live From Vietnam

A little wind noise, a little connectivity flakiness, and a little lip-sync issues from YouTube, but look at that view! 🤩 Back to business, it's the Brinks Home FAQ I found most interesting this week...
评论点赞收藏4 天前

尼泊尔政府加入Have I Been Pwned免费服务

尼泊尔成为第47个加入Have I Been Pwned免费政府服务的国家,其国家网络安全中心可监控政府域名内的数据泄露情况。HIBP政府服务旨在帮助各国网络安全团队提升威胁监控和事件响应能力。
评论点赞收藏9 天前

感谢 FedEx,这就是我们总被钓鱼的原因

安全研究员 Troy Hunt 收到 FedEx 包裹催款短信,逐条拆解7处可疑细节后,致电 FedEx 客服确认金额真实——原来 BPOINT 支付系统本身就用参数篡改生成链接,FedEx 自己长得像骗子。澳大利亚每年因诈骗损失超30亿澳元,技术拦截只是冰山一角,识别诈骗模式仍依赖人工。
评论点赞收藏11 天前

Weekly Update 515

Apparently, Aussies are so obsessed with coffee that it's referred to as the coffee capital of the world down here (some bits, at least). "But what about Italy?" people ask. Having spent a lot of time...
评论点赞收藏13 天前

第514周更新:本周数据泄露观察

特洛伊·亨特分析 Origin Energy 数据泄露事件的多方博弈:企业强调信用卡安全,黑客指责未获响应,双方达成和解但数据删除无保障。文章指出受害者需假设数据仍存风险,并回顾 Optus、Medibank 等过往案例,强调持续防御的重要性。
评论点赞收藏21 天前

第513周更新:Claude 串联家庭网络数据

特洛伊·亨特分享利用 Claude 整合 UniFi、Home Assistant 和 Pi-hole 数据的实战案例。文中记录了通过 AI 快速定位 Pi-hole 故障从而恢复 Sonos 音乐服务的具体经历,展示了生成式 AI 在家庭网络运维中的实际价值与信号提取能力。
评论点赞收藏26 天前

第511周更新:来自马拉喀什里亚特酒店的现场报道

特洛伊·亨特本周从马拉喀什分享数据泄露话题。他深入探讨在互联网上彻底删除个人数据的徒劳性,比喻为试图清除泳池中的尿液。虽然无法完全抹除痕迹,但仍有必要采取防御措施减少暴露面。这对关注隐私保护和技术安全的读者具有实用参考价值。
评论点赞收藏38 天前

泳池与尿液:为何你无法从互联网上彻底删除自己的数据

Troy Hunt 指出数据删除服务仅对合法合规的数据经纪商有效,面对泄露在黑市和论坛的被盗数据毫无作用。一旦数据泄露,就像往泳池撒尿,无法收回。这揭示了所谓“一键删数”服务的商业局限性和虚假承诺,提醒用户对隐私保护保持现实预期。
评论点赞收藏44 天前

Weekly Update 509

I know enough about home cinema audiovisual to know there's a lot I don't know. It's conscious incompetence, if you like, which is different to the unconscious incompetence most people have on the top...
评论点赞收藏53 天前

菲律宾政府正式接入 Have I Been Pwned 数据泄露监控服务

菲律宾国家CERT(计算机应急响应小组)正式成为第46个接入Have I Been Pwned(HIBP)免费政府服务的国家机构,现在可以持续监控本国政府域名在HIBP数据库中的泄露情况,为网络安全防护提供数据支撑。这是Troy Hunt个人项目在政府层面持续扩展的标志性节点,对关注全球数据泄露和政府安全能力建设的读者而言是一条具体、有时效性的动态。
评论点赞收藏74 天前

Weekly Update 506

I'm finding it quite fascinating to watch the current spate of ShinyHunters breaches and dumps. There's the obvious criminality of it all, but then there's also the response from organisations (or lac...
评论点赞收藏76 天前

欢迎不丹政府加入 Have I Been Pwned

今天,我们欢迎第45个入驻Have I Been Pwned免费政府服务的机构:不丹。不丹计算机事件响应团队(BtCIRT)现已能够利用HIBP中的数据,对不丹政府的域名进行监控。作为不丹的国家CIRT,BtCIRT负责处理各类威胁信息。
评论点赞收藏82 天前

欢迎巴哈马政府加入Have I Been Pwned

Today, we welcome the 44th government onboarded to Have I Been Pwned’s free gov service: The Bahamas. The National Computer Incident Response Team of The Bahamas, CIRT-BS, now has access to monitor go...
评论点赞收藏94 天前

欢迎孟加拉国政府加入Have I Been Pwned

Today, we welcome the 43rd government onboarded to Have I Been Pwned's free gov service, Bangladesh. The BGD e-GOV CIRT department now has full access to query all their government domains via API, an...
评论点赞收藏96 天前

每周更新 503:Instructure勒索截止期限

Well, it's the day before the Instructure "pay or leak" deadline (at least by my Aussie watch), and the company remains removed from the ShinyHunters website. In its place sits a press statement that ...
评论点赞收藏97 天前

登录芦苇

登录后关注作者、收藏内容和参与讨论。