1Password Can Tell If Your Password's Been Leaked

Data breaches spill the beans on our passwords so often that it's hard to keep track of which passwords are still safe to use. Fortunately, AgileBits, the company behind the 1Password password manager (a favorite among Apple users) has come up with a new weapon with which to test your passwords.

AgileBits didn't do it alone, though. The new Check Passwords option is built on the work of the trusted security researcher Troy Hunt, who's been letting people know if their passwords have been pwned for years.

MORE: Best Password Managers

How to Try It Yourself

The new tool, available now on the web-based version of 1Password (at 1Password.com), scans Hunt's database of more than 500 million leaked passwords  to see if yours is among them. I tried this out for myself with a few passwords of my own and was delighted to get the desired result of "Not found, way to go. :)" with each.

To test AgileBits' implementation of this tool for yourself, you'll need a 1Password subscription. (Sorry, but users of the 1Password desktop app who don't have a 1Password subscription won't be able to use this.)

Log on at 1Password.com, unlock your vault, open a login entry and hit a keyboard shortcut (Shift+Ctrl+Option on Macs, Shift+Ctrl+Alt+C on Windows) to unlock the feature.

If you hover over a password, you'll see a new Check Password button. Tapping that will tell you if your password's been leaked in any of the dozens of data breaches that Hunt has compiled.

Of course, you can also skip the middleman and try this without a 1Password account by entering any password at Hunt's Pwned Passwords site here.

Hunt recently overhauled the front end of Pwned Passwords to add more security enhancements. In the six months since his service originally launched, his database has grown from 320 million passwords to nearly 502 million.

What's most impressive about this situation is that only a mere 27 hours separated Hunt launching the new version of Pwned Passwords yesterday (Feb. 22, Australian time). As you might expect, Hunt was impressed by the turnaround time.

1Password's new feature works in conjunction with Hunt's anonymizing technology, which means your passwords are first hashed (disguised) with a SHA-1 one-way encryption algorithm. It's not even sending the whole hashed password, either, as Hunt's service requires only the first five characters of the 40-character hash.

For more of the technical nitty-gritty about what makes Hunt's new service so secure, check out his write-up here. We've reached out to AgileBits to see if they plan to add this feature to the stand-alone versions of 1Password.

TOPICS
Henry T. Casey
Managing Editor (Entertainment, Streaming)

Henry is a managing editor at Tom’s Guide covering streaming media, laptops and all things Apple, reviewing devices and services for the past seven years. Prior to joining Tom's Guide, he reviewed software and hardware for TechRadar Pro, and interviewed artists for Patek Philippe International Magazine. He's also covered the wild world of professional wrestling for Cageside Seats, interviewing athletes and other industry veterans.

Latest in Password Managers
The Apple Passwords app open on an iPhone in hand
Apple Passwords password manager review
A phone in hand showing the LastPass logo
Millions stolen from LastPass users in massive attack — what you need to know
Proton Pass
Proton Pass password manager review
A phone and tablet sharing passwords using Google Password Manager
Google just made a huge step in killing off passwords for good
Keeper password manager shown on laptop and smartphone
Hurry! Save 50% on this top-rated password manager
Keeper password manager shown on laptop and smartphone
Hurry! One of our top password managers is 50% off right now
Latest in News
Bill Gates in 2019
Bill Gates just predicted the death of every job thanks to AI — except for these three
NYTimes Connections
NYT Connections today hints and answers — Wednesday, March 26 (#654)
Gemini screenshot image
Google unveils Gemini 2.5 — claims AI breakthrough with enhanced reasoning and multimodal power
Samsung Galaxy Z Flip 6 review.
Samsung Galaxy Z Flip 7 design just teased in new cases leak — and the outer display is huge
Google Chrome
Chrome failed to install on Windows PCs, but Google has issued a fix — here's what happened
nyc spring day AI image
OpenAI just unveiled enhanced image generator within ChatGPT-4o — here's what you can do now
  • Corwin65
    So, if I give them MY passwords, they can leak them too?

    Sorry, not sharing my passwords with anyone.
    Reply
  • shawndugout13
    I agree. Not doing it. No password from me either.
    Reply
  • aquielisunari
    20735444 said:
    Password manager 1Password's latest feature lets you check whether your password has been leaked in a data breach.

    1Password Can Tell If Your Password's Been Leaked : Read more

    This feels like a Huffington Post article. Tell us your secret and then we will see if anyone knows it. Uhhhh. No, thanks.

    If your password is Password1234 somebody else has it. If your password is KLJHGOIY)*(&t9865sdg6+_(4367k,IOULH?><. the chances of someone having it are much less likely.
    Reply