Live Password Tester
Context
A password tester is a fairly common gadget — the interesting part here wasn't the feature itself but the privacy constraint: how to build it without ever letting a password, even a fictional one, touch a server.
What was done
Since the site runs on Blazor Server, a classic bound field (@bind) would have sent every keystroke to the server over the SignalR circuit. The tool therefore runs entirely in browser-side JavaScript, with no link to Blazor at all: entropy and crack-time estimates at several attack speeds (throttled login, slow hash, fast GPU hash, massive cluster), and a known-breach check via Have I Been Pwned's Pwned Passwords API using k-anonymity — only 5 characters of a locally computed SHA-1 hash are ever sent, never the password or its full hash.
Result
A public, working tool with a verifiable privacy guarantee: the password never leaves the browser.