Insecure secrets in core_samba

Vote for it to be an optional
Hope for enough votes
Hope devs listen to the community

Here’s the link: Opt~out/in Password check to third party

Meanwhile you can block the api call if you don’t want the notifications. (This also includes no check, if you can live with that). This can be done in a few ways, but a simple one is to have api.pwnedpasswords.com either blocked or resolved locally to 127.0.0.1.