{
  "id": 12703602,
  "title": "Check a Password Against a Breach List Without Sending the Password",
  "url": "https://urgent.news/2026/10/07/check-a-password-against-a-breach-list-without-sending-the-password",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-07T20:11:23.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/neulketing/check-a-password-against-a-breach-list-without-sending-the-password-4edf"
  },
  "original_language": "en",
  "account": "As of October 8, 2026, it's possible to check whether a password has been compromised without sending the full password over the internet. This is achieved by hashing the password locally and transmitting only a portion of the hash. The browser performs the SHA-1 hashing and sends the first five characters of the resulting hash as a prefix to the Pwned Passwords range endpoint. The server then responds with a list of suffixes that match this prefix, along with the number of occurrences for each suffix. The browser compares its own suffix against these candidates locally, without ever transmitting the remaining characters of the hash. This approach ensures that only a small amount of information is transmitted, reducing the risk of exposing the password itself. The developers should implement this check after a user action, such as submitting a form, rather than on every keystroke to minimize network traffic and potential exposure. It's important to note that a zero match in the Pwned Passwords database does not guarantee that the password is strong or unique, as the dataset only indicates whether the password has been found in a known breach. Additionally, the use of SHA-1 for hashing in this context is primarily for compatibility with the existing dataset and should not be used for secure password storage, as SHA-1 is considered unsuitable for that purpose. The provided JavaScript function demonstrates how to perform this local checking process.",
  "summary": "As of October 8, 2026 A password check can query a breach list without putting the password in an HTTP request. The browser hashes the input, sends five hexadecimal characters, and checks the returned candidates locally. We build small web tools, and we like this approach because the network boundary is explicit enough to inspect. Have I Been Pwned provides this pattern through its Pwned…",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}