DEV Community

Discussion on: React component for checking pwned passwords

imichael profile image

I realize that, but it's still deceptive and infringing to privacy. Does the user know their data is being sent haveibeenpwned? Do they agree before the data is sent?

Thread Thread
mxschmitt profile image
Max Schmitt Author

Nope, but I don't think that this is the job for this component. But I agree, that the user should know that their data despite that, that the password is very much anonymised send to the server of Have I been Pwned.