@i0null on a serious note, this is why I don't like it when sites, without my permission, check my password against "haveibeenpwnd" - even if they probably (I hope?!) use the hashed variant.. who says I trust that site?? wth
@bazkie if they do it properly then haveibeenpwned only sees like the first 5 characters of the password hash, or something. You don't have to trust haveibeenpwned.
I'd rather have checks against it than all this "must contain ..." nonsense. @i0null