Back to glossary

k-Anonymity

k-Anonymity for breach checks means only a hash prefix is shared, so your full password never leaves the device.

Last updated:

k-Anonymity in breach checking means your query is indistinguishable among many possible secrets. Have I Been Pwned’s range API receives only the first five characters of a password hash; your browser finishes the match locally.

How it works

Imagine searching a huge phone book without saying your full name. You send only the first few letters; the service returns every matching surname in that bucket; you privately check whether yours is in the list. In HIBP’s model, the “letters” are the first five hex characters of a SHA-1 digest of the password. The server never sees the complete hash or the plaintext.

Why it matters for passwords

It lets you learn whether a password appeared in known dumps without uploading the password itself. That is the privacy model behind PassTip’s breach tool — safer than pasting secrets into sites that accept full passwords over a form.

Practical example

You type a candidate password in PassTip’s breach check. The browser hashes it, sends only ABCDE… as a prefix, receives thousands of hash suffixes, and compares locally. If there is a hit, rotate that password everywhere it was reused.

Related terms

Related reading

PassTip tip

Check a password for breaches using k-anonymous hash prefixes — never paste secrets into tools that ask for the full password over a form they store.