Streisand effect in its best :) I wouldn't trust Troy. He was trying to put passwords checks using third-party APIs, Cloudflare and 1Password into Firefox code.
"k-anonymity" model which works like this: when searching HIBP for a password, the client SHA-1 hashes it then ... sends this to the API.
https://www.troyhunt.com/were-baking-have-i-been-pwned-into-...
What exactly appears to be the problem?
The reasoning for this feature is clearly laid out, and the underlying "ethics of running a database breach search service", while controversial, are also something Troy has thought about very carefully:
https://www.troyhunt.com/the-ethics-of-running-a-data-breach...
My trusted browser should not send out any sensitive information.