Has Your Password Been Breached?
Check password strength and see if it appeared in known data breaches. Uses k-anonymity - your actual password never leaves your browser.
How We Protect Your Privacy
We use the k-anonymity model from Have I Been Pwned. Your password is SHA-1 hashed entirely in your browser. Only the first 5 characters of that hash are sent to HIBP. The API returns ~1000 matching hash suffixes, and we check locally if yours is in the list - the full hash and your actual password never leave your device.
If HIBP cannot be reached, or answers with something other than its hash list, the breach row says the check did not run, and the password is not called strong: a password is only “not breached” when the list came back and it was not on it. A password that is on the list is cracked instantly, whatever its length, because attackers try breached passwords first.
Password Best Practices
- Use a password manager: Bitwarden, 1Password, or KeePass generate unique, strong passwords
- 16+ characters: Length matters more than complexity
- Passphrases: “correct-horse-battery-staple” is stronger than “P@ssw0rd”
- Never reuse passwords across sites - one breach exposes all
- Enable 2FA everywhere possible as a second layer of defense