Will this feature be enabled by default?
Can this be disabled?
Will this feature be enabled by default?
Can this be disabled?
https://haveibeenpwned.com/API/v2#SearchingPwnedPasswordsByR...
As far as HIBP linking your email to specific breaches, well, it is essentially using public data sets so that disclosure exists already (before HIBP even enters the picture). They are a bit more reserved with certain cases (the Ashley Madison breach for example), but even then if someone wanted to locate email addresses in that breach, they'd just go get that data set.
This feature has a potential in connecting a browser (instance/session/ip) to an email (even in the form of abbreviated hash), which I would consider a security risk.
They look at breached sites and rather or not you saved a login for that site on a date before the site was breached.