4 ms·
HIBP doesn't work that way really. You don't query for a site breach + email combination, you basically give your email address and then it returns back a list
by jsgo 7y ago
HIBP doesn't work that way really. You don't query for a site breach + email combination, you basically give your email address and then it returns back a list of breaches your email address was part of.
As far as HIBP linking your email to specific breaches, well, it is essentially using public data sets so that disclosure exists already (before HIBP even enters the picture). They are a bit more reserved with certain cases (the Ashley Madison breach for example), but even then if someone wanted to locate email addresses in that breach, they'd just go get that data set.
- java-man 7y agoAs long as this functionality can be disabled. This feature has a potential in connecting a browser (instance/session/ip) to an email (even in the form of abbreviated hash), which I would consider a security risk.