Abstract will be written later, but the is talk an early exploration of whether differential privacy and other tools can enable a password management service to safely learn aggregate data such as average password strength. The talk does not give an answer. But it lists challenges and some potential approaches.