They should really accept a hash of your email/username to lookup. Then we can an idea of if we've been pwned without giving additional information if we haven't been.
I'm not sure how that would help. They would have to generate a matching hash on their end, giving them a lookup table to work backwards from hash to email address.
Now if they wanted to supply a list of hashes to the public, then you could check your own without knowing any of the other addresses used to generate the remaining hashes.
Unless you use different usernames/email addresses for all the websites you sign up for, this website isn't any more or less random than any of the hundreds of websites you've punched your ID into (and of which some, more likely than not, has been compromised).
kevinoconnor7|11 years ago
jdludlow|11 years ago
Now if they wanted to supply a list of hashes to the public, then you could check your own without knowing any of the other addresses used to generate the remaining hashes.
rwallace|11 years ago
drivingmenuts|11 years ago
Maybe that's the next website to build: willihavebeenpwnd.com and then whenwillibepwnd.com
jgeorge|11 years ago
mseebach|11 years ago
superuser2|11 years ago
sprash|11 years ago
kazinator|11 years ago
Would you put your credit card info on a business card and give it to people you meet?
wglb|11 years ago