News: 1739422752

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Have I Been Pwned likely to ban resellers from buying subs, citing ‘sh*tty behavior’ and onerous support requests

(2025/02/13)


Troy Hunt, proprietor of data breach lookup site Have I Been Pwned, is likely to ban resellers from the service.

Have I Been Pwned (HIBP) has gathered data stolen in 866 breaches and appearing at thousands of paste sites, and allows anyone to search for email addresses or text that trove contains. If personal info is present in a data breach or paste site, HIBP advises users of the fact. Folk who find their addresses were pwned hopefully go on to do sensible things like reset passwords and enable multi-factor authentication.

HIBP also offers paid subscriptions that allow access to an API that handles bulk queries of its database. The subs range from $39.50 a year to $1,370.

[1]

In his [2]weekly update posted February 9th, Hunt explained that he suspected resellers were among his most difficult customers for those subs. Fueling that hunch was a support ticket lodged by a reseller that revealed they had marked up the price of the subscription from $1,100 to $2,544.

[3]

[4]

Hunt decided to crunch some numbers and quickly learned that just 0.86 percent of HIBP subscribers are resellers, but so far in 2025 they lodged 15.6 percent of support tickets. Further analysis suggested reseller support requests were more complex and took five times longer to handle than other queries.

After assessing those numbers, Hunt said “In all likelihood, probably this coming week, I think we're just going to ban resellers. I think we're just going to kick them off all together.”

[5]

Hunt said he’d drafted a blog post to explain the decision and hoped to post it this week. At the time of writing, no post has appeared.

Hunt told us he's decided to delay his decision.

In conversation with The Register , Hunt said he is now “Very, very, strongly inclined” to stop working with resellers, and plans to make a decision “in coming weeks.”

[6]

He told us HIBP feels allowing resellers to acquire subscriptions is “extraneous” to the business, which has tried to make its subscriptions as simple as signing up for a streaming video service. He's worked with resellers to help those who can’t pay by credit card or must follow formal procurement processes that don’t permit direct purchases.

[7]A million Australian pubgoers wake up to find personal info listed on leak site

[8]SCC, one of Europe's largest resellers, orders staff back to their desks for three days a week

[9]Microsoft's spat with ValueLicensing limps toward 2026 showdown

[10]Have I Been S0ld? No, trusted security website HIBP off the table, will remain independent

Hunt hopes to find a middle ground by developing automations that mean most reseller requests can be handled without human intervention, but feels they’ll continue to consume a disproportionate amount of support resources.

“Every time they come up for renewal they want a new quote,” he told The Register , in contrast to other customers that understand how subscriptions work, and that HIBP will occasionally hike prices.

In the video, Hunt bemoans one reseller who asked for a price rise to be reversed because their end-customers wouldn’t pay it. Another sent a long list of questions about matters including a returns and cancellations policy, to which Hunt retorted “What do you mean ‘return’? It's a subscription. How do you return your Netflix subscription?”

Hunt cited the incidents in the above paragraph as representative of “shitty” behavior from resellers. He promised to find ways to work with customers who currently acquire HIBP through a reseller.

He’s fonder of managed service providers (MSPs), who he feels add useful value.

The video also reveals that HIBP has automated responses to requests to have personal information removed from its data trove. Hunt said some people want all of their info removed, others are content to have their info retained without being publicly searchable, while some want their data excluded in records of new data breaches. HIBP previously explained those options in response to erasure requests. Now it’s built tech to automatically determine which of the three options people want, saving it a bit of time. ®

Get our [11]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offprem/channel&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Z63Q0cygvuGLPPoY0qjzWAAAAhc&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://www.troyhunt.com/weekly-update-438/

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offprem/channel&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Z63Q0cygvuGLPPoY0qjzWAAAAhc&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offprem/channel&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Z63Q0cygvuGLPPoY0qjzWAAAAhc&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offprem/channel&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Z63Q0cygvuGLPPoY0qjzWAAAAhc&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offprem/channel&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Z63Q0cygvuGLPPoY0qjzWAAAAhc&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[7] https://www.theregister.com/2024/05/02/australian_pubs_data_breach/

[8] https://www.theregister.com/2024/10/21/scc_rto_3_day_week/

[9] https://www.theregister.com/2025/01/06/valuelicensing_microsoft_trial_date/

[10] https://www.theregister.com/2020/03/03/have_i_been_pwned_no_longer_being_sold/

[11] https://whitepapers.theregister.com/



John_Ericsson

In this context, what is a reseller?

Phones Sheridan

Exactly what it says in the tin. They are selling his service, to other people and keeping a cut.

Lee D

I know of many cybersecurity firms who will happily do a "dark web" check for your passwords, where it's basically just regurgitated HaveIBeenPwned data with their brand on it.

I saw off at least two that my employers insisted I use because they actually didn't do anything that we couldn't do ourselves. Happy to have it as part of a "value-add" on an bigger service for convenience, but they were just reselling us HIBP content that we got in an email before they did.

HIBP has gone far more commercial in recent years, though, and I'm not sure of its utility as a ongoing paid-for service in the future except as part of such larger arrangements, so this might be cutting off his nose to spite his face. But that's for him to decide.

He's worked with resellers to help those who can’t pay by credit card

Roland6

What service!

There are many service providers that only accept card payments, or if they do offer a pay on invoice service it’s only for those customers who are making regular large purchases and have satisfied credit checking.

Troy, should probably increase reseller subscriptions that include support by x5 plus an admin fee if they don’t want to use card payments.

Says it all

ecofeco

‘What are customers actually getting from resellers other than massive price markups?’ asks Troy Hunt

Sigh

Lee D

Just say no, man.

API / reseller access is this much per month, and we'll notify you of price increases.

Done.

Don't get into discussions about discounts, quotes, refunds, etc. at all if you don't want to provide those.

This is how much it costs. Like it or lump it. The cancel button is right there if you don't like it.

Phones Sheridan

The issue here is companies with buying departments. That department procures everything from toilet paper to antimatter containment fields. The buyers have no technical knowledge of the product they are trying to obtain, it's just a part number to them, so trying to use technical reasoning with them will not work. You have 2 choices, 1) jump through all their hoops, 2) "This is the product and this is the price, and the service is provided as-is. Take it or leave it". Unless the customer is about to spend tens of thousands, I always go for option 2.

Resellers ?

Pascal Monett

I had no idea they existed for this.

I go to HIBP and check an email address, job done.

A reseller is just an asshole looking for a quick buck. Ban them and be done with it.

Hale Mail Rule, The:
When you are ready to reply to a letter, you will lack at least
one of the following:
(a) A pen or pencil or typewriter.
(b) Stationery.
(c) Postage stamp.
(d) The letter you are answering.