I pay for my email that gives me a lot of aliases and most of them have not been pwned yet. So with his tool I would be flagged as a bot. Honestly, doesn't sound like a great idea to be frank. There must be large swaths of people that have either been careful or have specific emails that they use for certain purposes that haven't been pwned. The question, what should happen if I haven't been pwned? Should I not be ab…
It's not his idea, he's saying that there are people out there who are already (mis)using the data for this.
> Applying "Pwned or Bot" to your own risk assessment is dead simple with the HIBP API and hopefully, this approach will help more people do precisely what HIBP is there for in the first place: to help "do good things after bad things happen".