3 ms·
> The only flaw I never understand with the above is cant the attacker just change the password like 10-15 times in 5mins, and thus "flush" out the old password
by tetrep 10y ago
> The only flaw I never understand with the above is cant the attacker just change the password like 10-15 times in 5mins, and thus "flush" out the old password?
In systems where you have the "can't use previous N passwords" when changing it, you also pair that with a "can't change password more than X times a time increment".