Shown in API docs under "Pwned Passwords overview" and links to here: https://www.troyhunt.com/enhancing-pwned-passwords-privacy-b...
That seems way too low.
For context: If you take just dictionary words from the world's 5 most popular languages, you'd have more than 0.5 million words.
https://haveibeenpwned.com/API/v2#SearchingPwnedPasswordsByR...
With a good cache, thatd save some bandwidth.
Maybe that's wishful thinking. I can't imagine checking new passwords more than a few dozen times per second at the most. Bigger sites probably just write their own password integrity tools.
Most places just enforce byzantine password requirements, 13 digits, must have ~, uppercase and a palindrome prime integer in it.
Obligatory password XKCD, think of the children. https://xkcd.com/936/
I use a memory trick to have very strong passwords, but most people probably wouldn't be willing to invest the effort.
Someday there will be a better way.
I made a start on a Ruby port too: https://github.com/Freaky/ruby-gcs - I have vague plans to finish it off and write a Rodauth (http://rodauth.jeremyevans.net/) plugin for it.
I wrote a devise extension thats essentially a one liner to add this check on signup (and a small code block to add on signin)
https://github.com/michaelbanfield/devise-pwned_password
Nowadays most of the logic is encapsulated in the pwned gem
https://github.com/philnash/pwned
Which is a good choice if you arent using devise.