Question about Watchtower vulnerable password integration with haveibeenpwned.com.
I have been reading both the 1Password and the haveibeenpwned documentation on your integration. It is a very interesting feature.
Since the integration occurs at the client level, and because only 5 hash characters are passed to haveibeenpwned.com, but potentially hundreds of hashes can be returned, I am guessing this could become a resource intensive process (eg. 200 passwords in 1Password x 500 records returned from haveibeenpwned would require 100K records to be processed on the client).
I further assume that this is not just a one-time process. You can't just check with haveibeenpwned when a password is created or modified, because any password could be reported in a breach at any time in haveibeenpwned, and that event would require a reprocessing of all the passwords stored in local client.
So how does this work? Is there a batch job which runs on the local client every day or every few days to check passwords against haveibeenpwned? If so, what is the average delay time between when a password is reported in haveibeenpwned and when it is reported in Watchtower?
Thanks,
Dean
1Password Version: Not Provided
Extension Version: Not Provided
OS Version: Not Provided
Browser:_ Not Provided
Referrer: forum-search:https://1password.community/search?Search=haveibeenpwned.com%20frequency
