6 comments

4
> To protect your privacy and security, the data that you enter in the search field is hashed, and we use only this hash to perform a search in our database. We do not collect entered emails or passwords, nothing is logged when you perform a leak check. Anyone else skeptical of this claim or am I just overly paranoid?
4
Indeed. Seems super shady. The bottom of the article they mention it. Really though don't enter your password anywhere they shouldn't go.
2
I use randomly generated passwords so the chance of any of them appearing in that list are astronomically small anyway.
2
You could just get the file (100 GB) and rg it yourself, or use Bitwarden, which has a handy little `Check Compromised` button next to password fields.
2
The original rockyou.txt: 60MB RockYou2021: 100GB [Largely a wordlist.](https://i.imgur.com/BerK7iU.png)
2
Compile all [these](https://wiki.skullsecurity.org/Passwords) plus some word lists, and you'll be in the same ball park. Also, show SkullSecurity some love for hosting comprehensive learning resources on his own dime at [patreon](https://www.patreon.com/iagox86)