Am I the only person worried about how this represent a potential violation of privacy? You can not only enter your e-mail address to see how you are affected, you could also put in the e-mail addresses of
other people, and boom, you can see what communities they have signed up for, assuming those sites have suffered a breach some time in the past. I might have given Last.fm my e-mail address during the signup process, for example, but I might not necessarily want the whole world to be able to determine that I have signed up for Last.fm.
Yes, I am aware that the breached data is already floating around on the internet, but it isn’t so convenient to consult it as on this website (or Have I Been Pwned?). These sites ought to require that a person prove they own that e-mail address before returning data concerning it.