You don’t have to send the password to determine if it’s pwned... they have a hashing scheme to determine if a password was in any leaks.
See https://haveibeenpwned.com/API/v3#SearchingPwnedPasswordsByR...
See https://haveibeenpwned.com/API/v3#SearchingPwnedPasswordsByR...
> GET https://api.pwnedpasswords.com/range/{first 5 hash chars}
The service is only receiving the first 5 hash chars and thus could not collect your password.
Or you could read the javascript code of the page when you visit it.
> var i = sha1(n).toUpperCase(),
> r = i.substring(0, 5);
> $.get('https://api.pwnedpasswords.com/range/' + r).done(function (n) ...
Or you could download the file and check it locally.
#!/bin/bash
baseurl="https://api.pwnedpasswords.com/range/"
read -s pass
hash=$(echo -n "$pass"|sha1sum)
hashhead=${hash:0:5}
hashtail=${hash:5:35}
curl -s ${baseurl}/${hashhead}|grep ${hashtail^^}
It'll dump the hash and the number of times the given password was found. If the password is not found it won't return anything.We who understand what's going on know it's perfectly fine, but it's hard to get that message across. Just like the first time you try to explain what a hash is to a non-technical person.