Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

There’s no perfect solution here: publish the raw data, and people who haven’t changed their passwords get cracked, or publish hashed (in some way) passwords, and people will crack the passwords themselves. (That said, I guess most crackers will just get the data straight from the source, but still.)


He does publish the passwords hashed, with the number of times each password was leaked (without salt and the weak sha1).


It is trivial to find (most) of the datasets HIBP uses


Incorporate a non profit and have it own the data and run the service? No different than Let's Encrypt.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: