I'm curious, I was logging into a website to download some trial software, in the mean time Chrome popped up asking if I wanted to save that password to their manager. I said 'Never' as usual, but I noticed they sent my password I typed regardless to their website url 'passwordleakcheck-pa.googleapis.com'
Anyone have any insight? This doesn't feel right.
edit: There's the likelihood it's the other way around? They're downloading a big list of leaked hashes and checking it locally...