PrivacyMEDIUM

HIBP Update - New Passkeys and Enhanced Privacy Features

Featured image for HIBP Update - New Passkeys and Enhanced Privacy Features
THTroy Hunt
Have I Been Pwnedk-anonymitydomain verificationAPIdata breaches
🎯

Basically, Have I Been Pwned added new features to help keep your data safer.

Quick Summary

Have I Been Pwned has rolled out major updates, including k-anonymity searches and automated domain verification. These changes enhance user privacy and streamline services for larger organizations. Now, users can protect their data more effectively while accessing critical breach information.

What Changed

Have I Been Pwned (HIBP) has undergone a significant transformation, evolving from a simple hobby project into a robust service used by millions. With hundreds of thousands of daily visitors and billions of compromised records processed annually, the platform is now introducing exciting new features. These updates aim to enhance user privacy and streamline operations for larger organizations.

Among the most notable changes are the introduction of k-anonymity searches and automated domain verification processes. These features are designed to protect user data while maintaining the effectiveness of the service. The new structure of subscription plans also reflects a shift to better accommodate different user needs, from small businesses to large enterprises.

How This Affects Your Data

The introduction of k-anonymity searches is a game-changer for user privacy. Previously, searching for an email address involved sending the actual email to HIBP, which could potentially expose personally identifiable information (PII). Now, users can create a SHA-1 hash of their email and only send the first six characters to the API. This means that HIBP cannot trace the search back to the original email address, enhancing confidentiality.

Additionally, the automated domain verification process simplifies how organizations can manage their domains. Previously cumbersome steps have been replaced with streamlined methods, allowing for quicker and more efficient verification. This is particularly beneficial for managed service providers (MSPs) who monitor multiple domains for their clients.

Who's Responsible

The updates come from HIBP's founder, Troy Hunt, who has been dedicated to improving the service since its inception. His focus on user privacy and data protection is evident in these new features. The revisions to the terms of service now allow MSPs to use HIBP for their customers, expanding the service's utility while ensuring compliance with privacy standards.

With these changes, HIBP is not only maintaining its commitment to user privacy but also adapting to the needs of larger organizations that require more robust tools for monitoring and protecting their domains.

How to Protect Your Privacy

To take advantage of these new features, users should consider subscribing to the appropriate plan that fits their needs. For those managing multiple domains or handling sensitive data, the Pro or High RPM tiers may be the best fit.

Additionally, organizations should implement the k-anonymity search method when querying HIBP to ensure that their users' email addresses remain confidential. By adopting these practices, users can enhance their privacy and security while utilizing HIBP's powerful resources effectively.

🔒 Pro insight: The shift to k-anonymity searches indicates a growing emphasis on privacy in breach monitoring services, setting a new standard for data protection.

Original article from

THTroy Hunt· Troy Hunt
Read Full Article

Related Pings

LOWPrivacy

Cindy Cohn Discusses Privacy on The Daily Show Tonight

Cindy Cohn is on The Daily Show tonight discussing her new book on online privacy. Tune in to hear her insights on digital rights and surveillance. Don't miss this important conversation!

EFF Deeplinks·
HIGHPrivacy

Apple's Privacy Feature Fails to Protect Users from Law Enforcement

What Changed Apple's privacy feature, Hide My Email, is designed to protect users by allowing them to create anonymous email addresses. This feature is particularly useful for those who want to keep their personal information private when signing up for apps or websites. However, recent events have revealed a significant flaw in this privacy promise. Federal agents have successfully

TechCrunch Security·
HIGHPrivacy

Secrets Sprawl - Key Takeaways for CISOs in 2026

Secrets sprawl has surged, with 29 million new hardcoded secrets found in 2025. Security teams must adapt to protect against rising risks. GitGuardian's report reveals critical insights for managing credentials effectively.

The Hacker News·
MEDIUMPrivacy

Apple’s Camera Indicator Lights - A Security Review

Apple has introduced a new camera indicator light to enhance user privacy. This hardware feature alerts users when the camera is active, countering potential malware risks. It's a vital step for protecting personal data in a digital age.

Schneier on Security·
MEDIUMPrivacy

Android 17 Enhances Location Privacy with One-Time Access

Google's Android 17 brings new location privacy features, allowing users to control access with a one-time button. This update enhances data protection and transparency.

Help Net Security·
MEDIUMPrivacy

Smart Home Breach - Lack of Government Guidance Exposed

A new study shows that government guidance for smart home breaches is lacking. Users often find themselves without clear steps to recover after a breach. This gap in support can leave households vulnerable and confused. It's time for better guidance on handling smart home security incidents.

Help Net Security·