Don't Take Security Advice from SEO Experts or Psychics

Beyond Passwords: 2FA, U2F and Google Advanced Protection

Why [Insert Thing Here] Is Not a Password Killer

Breaking Azure Functions with Too Many Connections

The Effectiveness of Publicly Shaming Bad Security

Mmm, Pi-hole

Extended Validation Certificates Are Dead

Why No HTTPS? Questions Answered, New Data, Path Forward

Why Your Static Website Needs HTTPS

The 111M Record Pemiblanc Credential Stuffing List

Why No HTTPS? Here's the World's Largest Websites Not Redirecting Insecure Requests to HTTPS

We're Baking ‘Have I Been Pwned’ into Firefox and 1Password

HTTPS is Easy

Pwned Passwords in Practice: Real World Examples of Blocking the Worst Passwords

86% of Passwords Are Terrible (and Other Statistics)

Subresource Integrity and Upgrade-Insecure-Requests Are Now Supported in Edge

Enhancing Pwned Passwords Privacy by Exclusively Supporting Anonymity

Have I Been Pwned Is Now Partnering with 1Password

The Legitimisation of Have I Been Pwned

Making Light of the “Dark Web” (and Debunking the FUD)

How Long Is Long Enough? Minimum Password Lengths by the World's Top Sites

"Pwned Passwords" V2 With Half a Billion Passwords

Why Searching Through 500M Pwned Passwords Is So Quick

I've Just Added 2,844 New Data Breaches with 80M Records to Have I Been Pwned

I'm Sorry You Feel This Way NatWest, but HTTPS on Your Landing Page Is Important

Face ID Stinks

The Trouble with Politicians Sharing Passwords

Don't tell people to turn off Windows Update, just don't

What I'm Telling US Congress about Data Breaches

The One Valuable Thing All Websites Have: Reputation (and Why It's Attractive to Phishers)

More →