3 ms·
I once used a system that stored old passwords as plaintext and searched for substring repetitions. Horrible.
by jagger27 5y ago
I once used a system that stored old passwords as plaintext and searched for substring repetitions. Horrible.
- rovr138 5y agoMicrosoft has that. Not plaintext, but encrypted (not hashed) with the idea that they can be used for things like that. https://docs.microsoft.com/en-us/windows/security/threat-protection/security-policy-settings/store-passwords-using-reversible-encryption https://docs.microsoft.com/en-us/windows/security/threat-pro...
- BrandoElFollito 5y agoThis is a good idea, if the passwords are the ones people change *from* (i.e. once you change your password, it gets into that list). This way nobody can use the password anymore (with the idea that it is a weak now, for any reason). This is selfish, though. If that database of passwords leaks, they are prime candidates to test on *other* sites.
- ben0x539 5y agoIf you encrypt the prior passwords using a key derived from the current password, you're enabling this sort of check on password change without really sacrificing security, don't you?
- dragonwriter 5y ago> If you encrypt the prior passwords using a key derived from the current password, How can you do that with a prior password if you didn’t store it as plaintext when it was current? You can’t encrypt something you don’t have. Unless you are encrypting the old hash, not the password.
- eropple 5y agoYou would have it during the password change if you did old-new-new_again, yeah?
- ben0x539 5y agoYeah that was the idea. I guess a lot of apps don't actually do that and just email you password reset links, in which case you can't actually recover the old password. :<
- rovr138 5y agoThis leaks data if a collision can be found and exploited. Assuming the user uses the password in other places, this can be a bad thing.
- dr-detroit 5y agoI am forced by management goons to give human resources database password in plaintext to indian/chinese developers who cannot grok typing a password but their job is sweet and better than mine but whites cant do database work dont be silly. Dont worry hr data isnt institutional only the poor suckers who work here are at risk.
- jnwatson 5y agoThe excellent (or horrible, depending on which end you're on) pam_pwquality[1] module for Linux allows rather fine-grained enforcement of how much a new password must differ from the old password. 1. https://www.systutorials.com/docs/linux/man/8-pam_pwquality/ https://www.systutorials.com/docs/linux/man/8-pam_pwquality/