Hacker News new | ask | show | jobs
by saagarjha 2306 days ago
I believe that Have I Been Pwned provides a useful service, but I find it very strange that needs to be valuated and sold like a startup when it’s essentially been able to survive because people singularly trust Troy with a bunch of illegally obtained material. Like, how do you buy that; how could you ethically and legally make money from it? Why can’t it just continue being supported by contributions?
3 comments

He explained a little bit about his thoughts on this in a previous blog post: https://www.troyhunt.com/project-svalbard-the-future-of-have...
I didn't find that very satisfying, unfortunately. He mentions that he's overloaded with trying to maintain the service, but then jumps immediately to looking for someone to acquire Have I Been Pwned. Couldn't he just get a few more people to help him out?
You say that like it's a simple thing.

I don't know the details of his particular situation, but it's entirely possible to grow a small company to the point where you either need to radically change your role, or find someone to do it for you. Acquisition is one way to do the latter, although it's not always going to be appropriate.

Sometimes you can't add a few people and have the same organization.

My takeaway is it kinda seems Troy wants to add A TON of people and still keep the same organization and responsibility.

Sounds to me like he's window shopping for an investor that will basically replace his engineering role with a team, pay that team, give Troy a paycheck for work he's done in the past, and let him show up every couple weeks between jetsetting to bark his vision at the new team.

I'm not shocked that it's not going well so far. HIBP is one of those unique cult-of-personality type platforms where it cannot exist in it's current form without Troy, and Troy cannot continue in his current form without HIBP. If I'm looking to buy HIBP I want to know that it's not just going to be the Troy Show 2.0 with my money instead of his.

I get the same impression to some extent, but I'd be hardpressed to say I wouldn't cave and do the same thing to be completely honest.

Who wants to work a 9-5 their entire life? I personally don't.

I agree. I was on the fence about my wording while posting because I can't say that given the opportunity I wouldn't shoot for the same outcome.
Right, but the link provided doesn't shed any light on the situation.
The way you buy that is by buying the thing that's trusted - that is, you buy Troy Hunt.

That realization appears to have been a major factor in the decision not to pursue other buyers.

A key feature of our society is that many things are given away for free and supported by an advertising infrastructure.
I emailed Troy to ask if he'd consider operating it as a non-profit utility similar to Let's Encrypt, and offered to help (because it's only fair if you come with an ask).
I've been sitting here wondering why bringing HIBP into an existing non-profit foundation wasn't the desired outcome. Having HIBP under the control of corporate interests seems icky.
Do we know for sure it wasn't? Couldn't Mr Hunt have wanted Mozilla to take over, but they weren't keen .. what other non-profit options fit here? Apache?
That sounds like a terrible idea in this case. It would all be ads for VPN services in the best case, or credit protection services in the worst case.