Also they can just query all the usernames (email addresses) of the accounts and get notifications if any of those usernames have appeared in breaches.
Also they can just query all the usernames (email addresses) of the accounts and get notifications if any of those usernames have appeared in breaches.
No, only you (well, your computer) knows if your password was found.
Essentially, the client hashes the password and then only sends the first 5 characters of the hash to HIBP. HIBP then returns the hashes of every password whose hash begins with the same characters (approx 477 matches, according to the article), and then it's up to the client to determine if there's a match.
That’s a ridiculously small number of possible values for a powerful actor trying to crack a password.
So it’s not all possible hashes with that prefix, it’s only the hashes of entries in the known passwords.
If the server was compromised, it would be able to know which users requested which hash prefixes and compare that to the “known hashes” that match that prefix. Not all passwords submitted are matches, but some are. And it’s likely that a users pattern of testing particular hash prefixes could make it much easier to crack a password.
[0] https://blog.cloudflare.com/validating-leaked-passwords-with...
Knowing the hash prefix of someone’s password doesn’t help you guess it. You can’t plan your guesses to have a matching prefix or anything. If your password is in the list, then the full hash is already out there and you should stop using it, because it’s probably been brute forced by someone or people are trying to guess it somewhere.