Information is provided about security practices


Status: PENDING
Changes: 0
Source: link
Author: docbot (21032) Bot


The password is hashed client-side with the SHA-1 algorithm then only the first 5 characters of the hash are sent to HIBP per the Cloudflare k-anonymity implementation. HIBP never receives the original password nor enough information to discover what the original password was. </p>
Created by Docbot version v3


Comments:
No comments found


We track editorial changes to analyses and updates to a point's status and display the previous versions here as part of an effort to promote transparency regarding our curation process. Unfortunately, for this point, due to how it was stored in our database, there are no previous versions available for display.