Google defends Gmail users from malicious nation state actors [1]. Isn't Nest part of the Google identity ecosystem now?
[1] https://security.googleblog.com/2012/06/security-warnings-fo...
Thank you to Troy Hunt
The scenario I was looking at was..
User signs up with Site A with Password 1.
User signs up with Nest with Password 1.
Site A gets compromised.
Nest couldn't know if you'd used the same password on each site. The only way they could know is if they used the same hashing algo with the same salt or SHA-1 with no salt. Highly unlikely.
I suppose Nest could check the Pwned Passwords API every time they logged in, but I haven't seen anyone deploy that yet, IIRC all solutions I've seen check Pwned Passwords API when the set the password. Setting a password and checking a password are often different systems.
I have no idea if it's integrated with their primary login flow though. It's certainly integrated with the password manager in Chrome.
One easy fix. Send a verification email to users when a different device is detected before allowing log in.
I mean, even Steam does this.