How to check whether a password has leaked, without giving it away
Before you send someone a password, it is worth knowing whether it is already on a list. Attackers do not guess passwords one letter at a time; they start with the huge lists that have leaked from other sites. The awkward part is checking without handing the password to yet another website. This guide explains how that is possible, and what PassAlong does with it.
Why a leaked password is a problem even if your account was never breached
When a site is breached, its users' passwords end up in collections that circulate for years. Those collections are used for credential stuffing: trying every leaked password against other services, automatically and at scale. It does not matter whether the leak was yours. If someone, somewhere, used the same password and it was exposed, it is among the first things an attacker will try.
So "has this password leaked?" really means "is this password on the lists attackers try first?" A password that is on them should not protect anything that matters, however long or clever it looks.
The obvious way to check is itself a leak
A form that asks you to type in your password and tells you whether it is safe has, by the time it answers, received your password. You would be trusting that site with exactly the thing you were trying to protect. Do not type real passwords into checkers that work like that.
How Have I Been Pwned checks without seeing the password
Have I Been Pwned is a free service that collects passwords from public breaches. Its password search is built around a technique called k-anonymity, which lets you check a password without revealing it:
- Your browser turns the password into a SHA-1 hash: a fixed string of 40 hexadecimal characters. The same password always gives the same hash, which is what makes it possible to compare without the password itself. Even so, the whole hash is not sent.
- Only the first five characters of that hash are sent. There are about a million possible five-character prefixes, and each one is shared by a great many different passwords.
- The service answers with every hash it knows that starts with those five characters, several hundred of them, each with a count of how often it was seen in breach data.
- Your browser looks for the rest of your hash in that list. The match, or the lack of one, is found on your device, and the answer never leaves it.
The response can also be padded with fake entries, so that its size does not give away how many real matches there were. What the service does see is what any server sees: that a request came from your IP address, and the five characters, which on their own do not identify the password.
How PassAlong uses it
When you type or paste a password into the box on the PassAlong home page, your browser runs this check against Have I Been Pwned:
- It waits until you stop typing for a moment, so there is one request, not one per keystroke.
- It sends only the five-character prefix, with padding switched on, and without cookies. Your browser talks to Have I Been Pwned directly. The request does not pass through our server, so we never see the prefix next to your IP address either.
- A line under the box says that the check is being made, whether or not it finds anything, so no request to a third party goes out unannounced.
- Generated passwords are not checked. A long random password from the password generator is not in any breach list by construction, and there is no point asking. Notes that run over several lines are not checked either: they are not passwords.
- It never stops you from sending. If the service cannot be reached, nothing is shown: it is a hint, not a gate.
None of this changes how the secret itself is handled. It is still encrypted in your browser before anything is sent, and the key stays in the part of the link after the #. The details are in How it works.
What the warning means
If the password is found, you see something like "This password has turned up 3,861,493 times in known data breaches". The number is how often it appears in the breach data, not how many sites were breached, and it is not about your account in particular. It means this exact password is known to people who build lists of passwords to try.
Any number above zero is enough. A password seen once is on the list as surely as one seen a million times.
What no warning does not mean
No match is good news, but it is not a certificate. The password may have leaked in a breach that has not been made public or collected yet. It may be short, or a name and a year, and easy to guess without any list. And a password that is safe today is not safe if you use it in five places and one of them is breached tomorrow.
If the password you were about to send has leaked
- Do not send it. Make a new one instead: the password generator produces a long random password in your browser, and it can go straight into a one-time link.
- Change it on the account it belongs to, and anywhere else the same password is used.
- Turn on two-factor authentication where the service offers it.
- If the old password has already been sent to someone, in an email or a chat, treat it as exposed twice over. What to do after sending a password by email goes through the steps.
The lasting fix is a different password for every account, kept in a password manager, so that one leak stays one leak. When a password does have to go to another person, send it through a link that opens once, as described in how to share a password with a colleague without leaving it in the chat.