Pemeriksa Kebocoran Kata Sandi
Uji kata sandi Anda dengan aman menggunakan algoritma k-Anonymity Have I Been Pwned. Hanya 5 karakter hash SHA-1 pertama yang dikirim, kata sandi asli tidak pernah keluar dari perangkat.
Only a 5-character fragment of this password's hash ever leaves your browser — never the password itself.
Enter a password to check it against known data breaches.
Cara kerja
Masukkan data Anda
Isi nilai yang diperlukan, tempel teks Anda, atau unggah file yang ingin diproses.
Lihat hasil seketika
Sebagian besar alat diperbarui secara langsung saat Anda mengetik; beberapa menggunakan satu tombol tindakan.
Gunakan hasil Anda
Salin, unduh, atau bagikan hasil yang dihasilkan — Anda selalu memiliki kendali penuh atas data Anda.
Apa itu Pemeriksa Kebocoran Kata Sandi?
Type a password to see whether it has turned up in a known data breach, without ever sending the password itself anywhere.
How to check if a password has been breached
How the check stays private
The password is hashed with SHA-1 right here in your browser. Only the first 5 characters of that hash are sent to our server, which forwards just that fragment to Have I Been Pwned's free Pwned Passwords API and gets back every suffix HIBP has recorded for that fragment — typically several hundred of them.
The comparison against your password's exact hash happens back in your browser, against that list. Neither our server nor HIBP ever sees the full hash, let alone the password — this is the same k-anonymity model HIBP documents for exactly this reason.
What a result means
A breach count is how many times that exact password has been seen across every dataset HIBP indexes, not how many times *your* account specifically was compromised. A password can be widely breached without your account being one of the exposed ones, because the same weak or reused password shows up under many different accounts.
A clean result only means this specific password is not in HIBP's current index. It is not a general safety guarantee, and it says nothing about whether an account using it was breached through some other route.
If a password comes back breached
- Stop using it anywhere, starting with the most sensitive accounts.
- Change it on every account that still uses it — reused passwords are what make a single breach costly.
- Use the Password Generator to create a new, unique password for each account, and store them in a password manager instead of memorizing them.
What actually leaves your browser
Your browser hashes the password locally and sends only a 5-character SHA-1 hash prefix to a ProntoUso server. The server forwards that prefix to Have I Been Pwned to retrieve possible matches; the exact comparison happens back in your browser. The password, full hash, prefix, and lookup response are not stored by ProntoUso.
Pertanyaan yang Sering Diajukan (FAQ)
Does ProntoUso ever see my password?
No. The password never leaves your browser in any form — only a 5-character fragment of its SHA-1 hash is sent, and even that fragment is not enough to reconstruct the password.
Why SHA-1? Isn't it broken?
SHA-1 is used here only because it's the specific format Have I Been Pwned's Pwned Passwords API expects for this lookup. It is not being used as a security mechanism to protect the password — it is a lookup key into a public breach index.
Is a breach count the number of times my account was hacked?
No. It's how many times that exact password string has been seen across every breach HIBP has indexed, regardless of whose account it belonged to.
What data source is this checking against?
Have I Been Pwned's Pwned Passwords service, a free, keyless, widely used index of passwords exposed in known data breaches.
Alat Terkait
- TersediaLokal
Generator Kata Sandi Kuat & Frasa Sandi (Passphrase)
Buat kata sandi acak yang kuat atau frasa sandi yang mudah diingat dan aman.
- TersediaLokal
Penghasil Hash
Hitung hash MD5, SHA-1, SHA-256, SHA-384, SHA-512, dan CRC32 untuk teks dan file.
- TersediaLokal
Penampil & Penghapus Metadata EXIF Foto
Lihat informasi kamera dan hapus metadata EXIF serta lokasi GPS dari foto Anda.
- TersediaLokal
Generator Header Content Security Policy (CSP)
Susun kebijakan keamanan header CSP untuk melindungi situs web dari serangan XSS.
- TersediaLokal
Pendekode Sertifikat SSL / X.509
Dekode dan periksa informasi sertifikat TLS/SSL PEM, masa berlaku, dan SAN.
- TersediaLokal
Penganalisis Header Email
Analisis header email mentah untuk melacak rute hop, SPF, DKIM, dan DMARC.
- TersediaServer
Pemindai Header Keamanan Web
Pindai dan evaluasi header keamanan HTTP situs web Anda (HSTS, CSP, XFO).
- TersediaLokal
Penghasil HMAC (Hash-based Message Authentication)
Hasilkan tanda tangan HMAC menggunakan kunci rahasia dan algoritma SHA.
- TersediaLokal
Generator & Pemeriksa Kunci SSH (Ed25519 & RSA)
Hasilkan pasangan kunci SSH (Ed25519 / RSA) aman atau periksa fingerprint kunci publik.
- TersediaLokal
Kalkulator Persentase Serbaguna
Hitung persentase dari suatu nilai, persentase kenaikan, penurunan, diskon, dan selisih.