Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

A much more honorable way to do this would have been to allow the search of a hash of your email rather than your actual email.


They do that, with the extra step of allowing k-anonimity (https://www.troyhunt.com/were-baking-have-i-been-pwned-into-...)


That's... exactly what they're doing?


Double-checking source code @ haveibeenpwned.com. I see no javascript that hashes your email address before submission.


Sure, but that's not what the linked article is discussing as the basis for integration with Firefox.


Well the email k-anonymity is new that he added for this integration and Troy addresses why he’s not yet using it on HIBP in the article.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: