#+HTML_HEAD: #+HTML_HEAD: #+EXPORT_FILE_NAME: index #+TITLE: Orion Orion is a simple cli client to check for compromised passwords using Have I Been Pwned API. *Note*: Your password is not sent anywhere, only the first 5 characters of the SHA-1 hash of the input is sent to HIBP API. * Working - Orion takes input from the user - Input is hashed & split (prefix: [:5], suffix: [5:]) - Prefix is sent to the HIBP API - HIBP API returns list of suffixes along with frequency - Orion looks for suffix from the list of suffixes Match means the password is present in HIBP database & has been compromised.