Check a password
Passwords from data breaches end up in lists that attackers try first. Here you see whether yours is among them. The password itself stays in your browser.
Enter the password
What happens technically
- Your browser computes a checksum
- The password is turned into a 40-character SHA-1 value. This happens on your device.
- Five characters go to our server
- Five characters do not allow the password to be recovered: hundreds of passwords in the list share the same beginning.
- We ask Have I Been Pwned
- Our server passes the five characters on. The service sees our address, not yours. The response is padded to a fixed length so its size reveals nothing.
- The comparison runs on your device
- A list of all endings for this beginning comes back. Your browser checks whether yours is among them. We do not learn the result.
- What we do not store
- Our application writes the five characters to no log. Our upstream proxy may keep the request address, including the five characters, in its access log for a short time. The page does not put the password into the browser history or storage.