Hash the phone number in the browser before sending it to your server. That way it is at least possible to verify via devtools what is being send.
Heck. Allow even prehashed phone number to be entered.
Heck. Allow even prehashed phone number to be entered.
The only way to check without giving up personal info is to get the data and look locally, or perhaps search for so many phone numbers that yours is buried in the haystack.
(Assuming seeing hacked numbers are public already - but I don’t love this either)
What’s a secure way of searching without disclosure by either party? (Non troll question)
Download the original data set. US records are around a GB file.