Hacker News new | ask | show | jobs
by eni 3040 days ago
How trustworthy is /haveibeenpwned.com? Is there a chance the password people enter there for checking will end up in the databases?
2 comments

There is almost zero chance Troy Hunt would torpedo his carreer doing something as monumentally stupid as that.

It's possible, sure. But I'd trust him with my password sooner than I'd trust [INSERT SV COMPANY HERE].

The article explains how the site has been designed not to send passwords to the server. Of course, it's up to you to decide if you trust them to keep it that way.