Skip to content

Check a password

Passwords from data breaches end up in lists that attackers try first. Here you see whether yours is among them. The password itself stays in your browser.

Enter the password

Your browser computes a checksum from the password. Only its first five characters are sent to us. After the check we clear the field.

What happens technically

How we check

Your browser computes a checksum
The password is turned into a 40-character SHA-1 value. This happens on your device.
Five characters go to our server
Five characters do not allow the password to be recovered: hundreds of passwords in the list share the same beginning.
We ask Have I Been Pwned
Our server passes the five characters on. The service sees our address, not yours. The response is padded to a fixed length so its size reveals nothing.
The comparison runs on your device
A list of all endings for this beginning comes back. Your browser checks whether yours is among them. We do not learn the result.
What we do not store
Our application writes the five characters to no log. Our upstream proxy may keep the request address, including the five characters, in its access log for a short time. The page does not put the password into the browser history or storage.