3 ms·
That thought requires the users to actually use new and unique passwords on every reset. If the attacker knows that your password is "Password1!!!!", it's prett
by dvcc 10y ago
That thought requires the users to actually use new and unique passwords on every reset. If the attacker knows that your password is "Password1!!!!", it's pretty easy to guess that the next time it asks you for a password it will be "Password1!!!!!". We're all computationally lazy after all.
I feel like the notifications that X device was recently used to login from Y IP/location solve that problem in a much easier way.