So yes sifting through billions of records will take a while, but it's possible, but telling the user the source of the details (and not the leaked passwords themselves) is exactly what his website mostly already does so it's not a risk.
So yes sifting through billions of records will take a while, but it's possible, but telling the user the source of the details (and not the leaked passwords themselves) is exactly what his website mostly already does so it's not a risk.
The risk is enabling a service that unlocks a capability like “give me the password for this email address that may or may not be mine”.
The source of a breach is a single attribute that can be associated with an entire dataset, unlike passwords.
Google: "leak-name-here download"
Because he does provide the email and the leak name... He even provide indirectly where to download it from his blogpost.
Providing the website won't give more dangerous information, that's exactly what he usually does when it's not a stuffing list, he say where the password come from (Linkedin, Facebook, etc...).
I want to know which service (https://www.troyhunt.com/content/images/2024/01/image.png) my details were linked with.
The compromised password can and should be deleted by them, and ignored by us.