k-Anonymity
k-Anonymity for breach checks means only a hash prefix is shared, so your full password never leaves the device.
Last updated:
k-Anonymity in breach checking means your query is indistinguishable among many possible secrets. Have I Been Pwned’s range API receives only the first five characters of a password hash; your browser finishes the match locally.
How it works
Imagine searching a huge phone book without saying your full name. You send only the first few letters; the service returns every matching surname in that bucket; you privately check whether yours is in the list. In HIBP’s model, the “letters” are the first five hex characters of a SHA-1 digest of the password. The server never sees the complete hash or the plaintext.
Why it matters for passwords
It lets you learn whether a password appeared in known dumps without uploading the password itself. That is the privacy model behind PassTip’s breach tool — safer than pasting secrets into sites that accept full passwords over a form.
Practical example
You type a candidate password in PassTip’s breach check. The browser hashes it, sends only ABCDE… as a prefix, receives thousands of hash suffixes, and compares locally. If there is a hit, rotate that password everywhere it was reused.
Related terms
Related reading
PassTip tip
Check a password for breaches using k-anonymous hash prefixes — never paste secrets into tools that ask for the full password over a form they store.