Have I Been Pwned goes open source, starting with the Pwned Password code; FBI to begin sharing compromised passwords discovered in investigations with the site
Want to find out if someone's stolen your user IDs and passwords? Then you can use “Have I Been Pwned,” and now the code behind it is being open sourced.
Context & Ripple Effects
Have I Been Pwned had already become infrastructure for password-risk checks: its Pwned Passwords API was adopted by 1Password, and breach search later reached 1Password Watchtower and Firefox Monitor. Troy Hunt had also signaled an intention to open-source the code base.
This report joins that software-opening step to a new public-sector data channel, with the FBI set to contribute passwords uncovered in investigations. The model was subsequently echoed when the UK's National Crime Agency shared compromised passwords with the service.
First-order effects
- Developers can inspect and reuse the Pwned Passwords code, extending a service that password managers and browser-facing tools already use for exposure checks.
- Have I Been Pwned gains a new planned source of compromised-password data from FBI investigations, while the FBI gains a route for making that intelligence useful to credential-defense tools.
Second-order effects
- 1Password Watchtower and Firefox Monitor become more dependent on Have I Been Pwned as a shared upstream layer for password-exposure alerts rather than maintaining separate breach-intelligence pipelines.
- The FBI arrangement establishes an operational precedent for law-enforcement contributions that the National Crime Agency later followed, widening the potential contributor base beyond breach disclosures and public dumps.
Third-order effects
- If agency contributions and open code continue together, credential defense shifts toward shared, inspectable infrastructure linking investigators, security-product providers, and end users rather than isolated breach-notification services.
The trend: Credential-security services are becoming ecosystem infrastructure, combining open implementations with shared breach intelligence from public agencies and consumer-security products.