Urgent.News

What's breaking now, across thousands of outlets.

Tech

Check a Password Against a Breach List Without Sending the Password

As of October 8, 2026 A password check can query a breach list without putting the password in an HTTP request. The browser hashes the input, sends five hexadecimal characters, and checks the returned candidates locally. We build small web tools, and we like this approach because the network boundary is explicit enough to inspect. Have I Been Pwned provides this pattern through its Pwned…

As of October 8, 2026, it's possible to check whether a password has been compromised without sending the full password over the internet. This is achieved by hashing the password locally and transmitting only a portion of the hash. The browser performs the SHA-1 hashing and sends the first five characters of the resulting hash as a prefix to the Pwned Passwords range endpoint.

The server then responds with a list of suffixes that match this prefix, along with the number of occurrences for each suffix. The browser compares its own suffix against these candidates locally, without ever transmitting the remaining characters of the hash. This approach ensures that only a small amount of information is transmitted, reducing the risk of exposing the password itself.

The developers should implement this check after a user action, such as submitting a form, rather than on every keystroke to minimize network traffic and potential exposure. It's important to note that a zero match in the Pwned Passwords database does not guarantee that the password is strong or unique, as the dataset only indicates whether the password has been found in a known breach.

Additionally, the use of SHA-1 for hashing in this context is primarily for compatibility with the existing dataset and should not be used for secure password storage, as SHA-1 is considered unsuitable for that purpose. The provided JavaScript function demonstrates how to perform this local checking process.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

Xbox Denies GTA 6 Will Stream Exclusively or to PC

Xbox has denied a report suggesting that Grand Theft Auto VI could stream exclusively through its cloud service or become playable on PCs at launch. The confusion began Oct. 6, when The Verge reported that Xbox had secured exclusive rights to stream Grand Theft Auto VI through the cloud, a service that runs games on […]

More from Wednesday 7 October →