← Back to projects Cybersecurity — Interactive tool, testable online

Live Password Tester

JavaScriptWeb Crypto APIHave I Been Pwnedk-anonymat

Context

A password tester is a fairly common gadget — the interesting part here wasn't the feature itself but the privacy constraint: how to build it without ever letting a password, even a fictional one, touch a server.

What was done

Since the site runs on Blazor Server, a classic bound field (@bind) would have sent every keystroke to the server over the SignalR circuit. The tool therefore runs entirely in browser-side JavaScript, with no link to Blazor at all: entropy and crack-time estimates at several attack speeds (throttled login, slow hash, fast GPU hash, massive cluster), and a known-breach check via Have I Been Pwned's Pwned Passwords API using k-anonymity — only 5 characters of a locally computed SHA-1 hash are ever sent, never the password or its full hash.

Result

A public, working tool with a verifiable privacy guarantee: the password never leaves the browser.

Une erreur inattendue est survenue. Recharger 🗙