3 ms·
multiple salts can be stored, no? and they can still figure out the same password. Google does the same, even going back multiple passwords in the past ("this p
by why-el 4y ago
multiple salts can be stored, no? and they can still figure out the same password. Google does the same, even going back multiple passwords in the past ("this password was used previously X years ago").
- vorador 4y agoHow would you check that across accounts if you had per-user salts though?
- why-el 4y agoAh I see, that I don't know (and I misread the original, quite correctly concerned post, my apologies). I am a customer and I will follow up with them about this. If I were to guess, they mean same accounts within the same organization, in case account setup has been automated.
- vorador 4y agoYeah, that makes sense!
- why-el 4y agoThis is the response I got: > Sorry, that part of the email wasn't clear. We don't compare passwords between Heroku accounts, this was more of encouragement so customers will hopefully practice good password hygiene.
- throwawayboise 4y agoThey could in theory hash the new password with every salt on every other account and see if there is a match... but that seems unrealistic, and if they can do it, it would imply that they are not using a slow hash algorithm such as bcrypt.
- adrr 4y agoIt is easy to determine previous password. Just store the previous hashes with the salt and check it when the user changes the password. The too similar checks are easy when you require the previous password. You can compare the new and old passwords together.