| Attack scenario | Estimated time |
|---|
Checks the free Have I Been Pwned "Pwned Passwords" database using k-anonymity: only the first 5 characters of your password's SHA-1 hash are sent, the full hash and password never leave this device. See "How the breach check works" in Settings for details.
These are used to pre-fill the Generator each time the app opens.
The free Have I Been Pwned "Pwned Passwords" API uses k-anonymity: this app computes the SHA-1 hash of your password locally, then sends only the first 5 characters of that hash (the "prefix") to the API. The API returns every hash suffix in its database that shares that prefix - typically several hundred - and this app checks locally whether your password's own suffix is among them. Your real password, and even your password's full hash, never leaves this device. This is the same technique used by browser built-in breach warnings.
This app never writes a typed or generated password to disk, in this app or anywhere else, and never transmits one anywhere - the only network call it makes is the opt-in breach check above, which sends a 5-character hash prefix only. This is a strength and generation tool, not a password manager - it does not store or sync your passwords for later retrieval.