SHA-1
SHA-1 is a cryptographic hash used by some breach corpora for lookups — not a modern choice for storing account passwords.
Last updated:
SHA-1 is a hash function that maps data to a fixed-size digest. HIBP’s password corpus historically uses SHA-1 digests for range lookups.
How it works
A hash compresses arbitrary input into a fixed-length fingerprint. For breach range queries, only a short prefix of that fingerprint is sent to the API (k-anonymity); matching finishes on your device. That is a lookup format, not a recipe for how apps should store user passwords.
Why it matters for passwords
Do not confuse lookup formats with password storage. Applications should store passwords with modern KDFs (for example Argon2 or carefully configured PBKDF2), not raw SHA-1. SHA-1 appears in breach-check pipelines for compatibility with existing corpora.
Practical example
PassTip’s breach check hashes your candidate with SHA-1 in the browser, sends the first five hex characters to HIBP, and compares suffixes locally — your full password never leaves the device.
Related terms
Related reading
PassTip tip
PassTip’s breach check follows HIBP’s SHA-1 prefix model in the browser. Open breach check.