news.volyx.in

I'm Open Sourcing the Have I Been Pwned Code Base (troyhunt.com)

722 points by vquemener · 2248 days ago · 133 comments on HN

Article summary

The creator of Have I Been Pwned (HIBP) is open-sourcing the code base to make the project more sustainable and community-driven. The decision comes after a failed merger and acquisition process, which made the creator realize the importance of community contributions. The code base will be opened up incrementally, with the goal of making the project self-sustaining. The data used by HIBP, however, is not being open-sourced due to its sensitive nature.

Main themes

  • open-sourcing
  • community-driven
  • data privacy
  • sustainability
  • security
  • merger and acquisition
  • code base management
  • breach data management

What commenters say

  • Open-sourcing HIBP's code base is a positive step towards making the project more sustainable and community-driven.
  • The code base being open-sourced does not necessarily mean that the data will be open-sourced, and there are valid reasons for keeping the data private.
  • Some commenters believe that open-sourcing the code base is a marketing tactic with potential downsides, while others see it as a way to make the world a better place.
  • The value of HIBP lies in its data, not its algorithm, so open-sourcing the code base does not compromise its uniqueness.
  • There are concerns about the potential consequences of making breach data available, including the risk of password cracking and exploitation.
  • Others argue that breach data is already available to those who know where to look, and that making it more accessible could have benefits for research and security.
  • The open-sourcing of HIBP's code base raises questions about the potential for other organizations to replicate the project and potentially eclipse it.
  • Some commenters believe that the code base should have been open-sourced from the start, while others understand the reasons for keeping it private until now.