you are viewing a single comment's thread
view the rest of the comments
[–] 3 points 3 days ago (2 children)

Do you want your password to be sent raw into a service to analyze your password entropy and detect common patterns, OR do you want a simple rule which can be checked client side?

  • source
  • hideshow 2 child comments
  • [–] 5 points 3 days ago

    You don't send full raw hashes, k-anonymity is a thing. HaveIBeenPwned just takes the first 5 of a hash and sends you back a list that you compare clientside so it never leaves as a usable password.

  • source
  • parent