OTOH, it's kind of difficult to begrudge Troy gaining financially from HIBP, since he's spent years building it up and has helped increase security awareness for so many people.
OTOH, it's kind of difficult to begrudge Troy gaining financially from HIBP, since he's spent years building it up and has helped increase security awareness for so many people.
It makes sense to tie it into the Firefox Account password manager too. Mozilla could leverage Troy's close connections with industry to have Firefox as the recommended secure & open-source option for enterprise clients.
Something that hasn't been touched on as much is the limitations that come with contracts for large commercial companies. Side projects are often expressly forbidden. Yes, Google with give you 20% time to work on your own ideas, but you can't then upload it to your personal website and call it your own - it becomes company property and may never see the light of day. I imagine that Mozilla are more open-minded in that respect. They also have plenty of experience with remote teams, which would work well for his family/travel tradeoffs.
Please, Mozilla - if this opportunity is offered to you, take it.
https://www.translatetheweb.com/?from=&to=en&a=https://t3n.d...
Though just realised, they're not that upfront about giving HIBP credit - If I were Troy this would peeve me a bit.
I think they discussed HIBP in the launch announcement: https://blog.mozilla.org/security/2018/11/14/when-does-firef...
It's also in the FAQ: https://support.mozilla.org/en-US/kb/firefox-monitor-faq
Was a little peeved at what seemed like a copy, but I have now realised it is just building on top of Troy's work [1] which is even better because of Firefox's larger reach.
They don't have to have a blinking marque text at the top attributing it to Have I Been Pwned. But they could have mentioned it on the front page somewhere that HIBP is one of their main sources. I trust HIBP, therefore, more value to Firefox Monitor had I known that link.
[1] https://www.troyhunt.com/were-baking-have-i-been-pwned-into-...
If you trust HiBP, you don't really need Firefox Monitor. It was created specifically to reach people that HiBP could not reach.
Maybe an organisation not involved in advertising at any level.
But I, personally, would now trust Mozilla with this, were there to take ownership.
"Troy Approved!"
Mozilla is a good group, they've had missteps but I find them trustworthy and the combination would be pretty trustworthy IMO.
I don't know how much has changed since I left Mozilla, but there were, and probably still are, a number of former employees and volunteer contributors that had a great degree of influence and input on various projects.
Heck, Troy might even be a good potential addition to the Mozilla board of directors at some point in the future.
Since Troy will still be involved, hopefully he can steer things in a direction that benefits everyone - or at least warn the public otherwise.
Another weird thought is that it's the sort of "baseline infrastructure" that should be "governmental" to the internet. Unfortunately the closest I can think to an existing model for that is ICANN and that may not be something to emulate.