Integrate haveibeenpwned with Brave's Password Manager

This feature will help us stay safe as it’ll inform us in the browser when our passwords have been leaked.

Please also include the option to run it locally in the browser through the downloader, which would auto-update, along with the API option.

Some context on haveibeenpwned:

Troy Hunt is a respected and trusted security guy in the Australian infosec industry and beyond. You can google him in the local news here.

And from wiki
Troy Hunt - Wikipedia
Have I Been Pwned? - Wikipedia

Hunt launched Have I Been Pwned? on 4 December 2013 with an announcement on his blog. At that time, the site had just five data breaches indexed: Adobe Systems, Stratfor, Gawker, Yahoo! Voices, and Sony Pictures.[20]

However, the site now had the functionality to easily add future breaches as soon as they were made public. Hunt wrote:

Now that I have a platform on which to build I’ll be able to rapidly integrate future breaches and make them quickly searchable by people who may have been impacted. It’s a bit of an unfair game at the moment – attackers and others wishing to use data breaches for malicious purposes can very quickly obtain and analyse the data but your average consumer has no feasible way of pulling gigabytes of gzipped accounts from a torrent and discovering whether they’ve been compromised or not.

Unsuccessful effort to sell

Midway through June 2019, Hunt announced plans to sell Have I Been Pwned? to a yet to be determined organisation. In his blog, he outlined his wishes to reduce personal stress and expand the site beyond what he was able to accomplish himself.[ 5]

As of the release of the blog post, he was working with KPMG to find companies he deemed suitable which were interested in the acquisition. However, in March 2020, he announced on his blog that HIBP would remain independent for the foreseeable future.[2 1]

Open-sourcing

On August 7, 2020, Hunt announced on his blog his intention to open-source the Have I Been Pwned? codebase.[ 22 ]

Hunt started publishing some code on May 28, 2021. [ 23]

I believe this costs some money to integrate and (not 100% sure on that or how much it is but) Brave’s password manager is free, so… :man_shrugging:

Relevant GitHub issue:

1 Like

It’s free:

2 Likes

This has been on the radar and discussed for a while. I see @User.1.000.000.000 shared one of the Github issues for it. Also below is a reply from @fmarier on a similar topic last year:

I’m not entirely sure what the status is on this. Nor whether your request may be a bit more comprehensive (if it might check things like emails in autofill, similar to HaveIBeenPwned does, rather than just checking passwords)

1 Like