Weekly Update 498
Get the full intelligence
Search transcripts, export clips, track mentions, and explore all topics from “Weekly Update 498” inside PodZeus.
In this episode of Troy Hunt's Weekly Update Podcast, Troy dives into a recent data breach investigation using his automated Open Claw system, detailing how he extracts and verifies email addresses from a public hacking forum. He shares frustrations around managing enterprise customers who delay payments despite 30-day terms, highlighting a particularly egregious case where a subscriber remained six months overdue. This leads to a broader discussion about the operational challenges of running a small, customer-focused service like Have I Been Pwned (HIBP), including manual invoicing, reconciliation, and the emotional toll of chasing unpaid bills. In contrast, Troy celebrates major updates to HIBP, including the launch of a new tiered pricing model with Core, Pro, and High RPM plans, the introduction of k-anonymity for privacy-preserving searches, automated domain verification via API, and the addition of passkeys for seamless login. He emphasizes that these changes aim to streamline operations, reduce reliance on complex enterprise agreements, and improve user experience while maintaining security. Troy also reflects on the irony of Fortune 500 companies claiming they can't use credit cards—despite doing so routinely in everyday business—reinforcing his commitment to Stripe as the primary payment method. Key takeaways include: 1) Automating payment enforcement through Azure functions to cut off service for overdue invoices; 2) Restructuring HIBP’s pricing and plans to cap domain usage and discourage reselling; 3) Introducing passkeys for faster, more secure login without adding new security layers; 4) Prioritizing credit card payments via Stripe to avoid the overhead of invoicing and legal redlining; and 5) Using Cloudflare caching and asynchronous key validation to dramatically improve performance. Troy concludes with a passionate defense of his service’s values—simplicity, automation, and direct accountability—while acknowledging the emotional weight of running a mission-driven business in a world of complex corporate bureaucracy.
Automate payment enforcement by cutting off service for overdue invoices using Azure functions.
Restructure HIBP plans with domain caps and tiered pricing to prevent abuse and reselling.
Introduce passkeys for faster, frictionless login without compromising security.
Prioritize Stripe and credit card payments to avoid the overhead of enterprise invoicing.
Use Cloudflare caching and asynchronous validation to reduce latency by 40%.
…and 3 more takeaways available in PodZeus
Investigating a New Data Breach with Open Claw
“I literally have my open claw commenting on hacking forums in order to get data that has been posted there.”
The Frustration of Enterprise Customers and Payment Delays
“You can't keep using services for free, getting upset when we turn it off because you haven't paid.”
Automating the Pain: Building a Payment Enforcement System
“It's easy to be tough when you can automate it. It's hard to be tough when it's literally Charlotte having to go in and look at who hasn't paid and send a manual email.”
Major Updates to Have I Been Pwned: New Plans, Passkeys, and Privacy
“We hope that pulls some of those customers down into pro. Canaanimity is cool.”
“You can't keep using services for free, getting upset when we turn it off because you haven't paid.”
“No Fortune 500 company is going to pay for services like this via credit card.”
“I literally have my open claw commenting on hacking forums in order to get data that has been posted there.”
Host
Troy Hunt
person
Have I Been Pwned
other
Open Claw
product
Stripe
other
Cloudflare
other
Stefan
person
Xero
product
Azure API Management
other
Charlotte
person
MSP
organization
Get the full intelligence
Search transcripts, export clips, track mentions, and explore all topics from “Weekly Update 498” inside PodZeus.
Start discovering podcast insights today
Start with a 7-day trial and explore a growing catalog of popular podcasts. No credit card required.
No credit card required • 7-day trial • Cancel anytime
