I think it's a good study in game theory at the least.
I think it's a good study in game theory at the least.
See https://haveibeenpwned.com/API/v3#SearchingPwnedPasswordsByR...
We who understand what's going on know it's perfectly fine, but it's hard to get that message across. Just like the first time you try to explain what a hash is to a non-technical person.
> GET https://api.pwnedpasswords.com/range/{first 5 hash chars}
The service is only receiving the first 5 hash chars and thus could not collect your password.
Or you could read the javascript code of the page when you visit it.
> var i = sha1(n).toUpperCase(),
> r = i.substring(0, 5);
> $.get('https://api.pwnedpasswords.com/range/' + r).done(function (n) ...
Or you could download the file and check it locally.
#!/bin/bash
baseurl="https://api.pwnedpasswords.com/range/"
read -s pass
hash=$(echo -n "$pass"|sha1sum)
hashhead=${hash:0:5}
hashtail=${hash:5:35}
curl -s ${baseurl}/${hashhead}|grep ${hashtail^^}
It'll dump the hash and the number of times the given password was found. If the password is not found it won't return anything.