I'm sure there's nothing to go wrong with that wonderful plan! Taking control away from the user is a great idea!
Except that it's not.
I'm sure there's nothing to go wrong with that wonderful plan! Taking control away from the user is a great idea!
Except that it's not.
Basically, it asks for all pwned hashes that start with the same 5 characters as your password's (hex-encoded) hash. So yes, there is an information leak (the first 5 characters of your hash), but it's an extremely unimportant one. Even knowing the first 5 characters, there's still 2^140 possible hashes it could be. And of course they would then need a pre-image attack on SHA1 to deduce your actual password from that.
More detail here: https://www.troyhunt.com/were-baking-have-i-been-pwned-into-...
Finally, I'm sure this option will be possible to disable, probably in settings but certainly in about:config.
Could it not download a list of a every site that has ever been hacked along with their domain list and the date of the hacking, then warn you if you have a saved password for one of those domains that was saved before the domain was hacked?
Because that's what it does.