LMAO
If you go to
haveibeenpwned.com
They literally ask you to put in your password, to check if it's been compromised.
Yeah I'm gonna trust you guys who already have a huge big database of stolen passwords, how do you get those exactly?
right, that's what I mean, they must be pretty well connected to deep web carder markets to keep their db up to date
Sooooo Couldn't they just take those passwords people give them, and sell them? and then turn around and say 'oops your password has been compromised'
Some Sucker: Dammit I keep changing it! How do they keep getting my password?
I'm sure, but then you have to just trust they're telling the truth, or that they are doing things as securely as they claim they are.
I guess the alternative is to distribute a big ass sql file, but that would be illegal, so we have to trust the private company who collects stolen information
Sure, but I'm just inclined to that kind of practice is encouraging bad habits, since you can't possibly expect the average user to examine the API and a lot of 'trusted' companies have been totally pwned or exposed as criminals themself.
Putting in one's email or social media account or other information is might be acceptable, but the pw itself?
well they word it like this
{ HaveIBeenPwned.com (HIBP) is owned and operated by Superlative Enterprises Pty Ltd ABN 62 085 442 020 ("Superlative", "we" or "us" }