It MIGHT not be as bad as you think. If the UI was just terrible at communicating and what it actually meant was, “that password is in our database of known compromised passwords,” then that would be reasonable. Google does this now too, but I think they only do it after the fact (e.g. you get a warning that your password is in a database of compromised passwords).
It MIGHT not be as bad as you think. If the UI was just terrible at communicating and what it actually meant was, “that password is in our database of known compromised passwords,” then that would be reasonable. Google does this now too, but I think they only do it after the fact (e.g. you get a warning that your password is in a database of compromised passwords).