Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Here's what I'm suggesting: query all your current passwords against the password API. Then you'll know which of your current password are compromised. Change them.

You don't need to query old passwords, only current passwords. If you're talking about accounts that you've forgotten the password to: then do you care about those accounts? If yes, probably best to do a password reset and set a new password. If you don't care about the account, then why bother?

As for why HIBP doesn't provide an API linking passwords to emails: HIBP has no database that links passwords and emails. So they can't provide any way to query that. They don't want to be in the business of linking passwords to emails.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: