3 ms·
We only store hashes of your previous passwords - we never store them in plaintext. We don't have the ability to enforce a silly requirement like "none of the
by mkjones 14y ago
We only store hashes of your previous passwords - we never store them in plaintext. We don't have the ability to enforce a silly requirement like "none of the n grams in a new password can be the same as those in an old password."
- bostonpete 14y agoWhy not? Doesn't the user have to enter both the old and the new when they're changing passwords?
- mkjones 14y agoSorry I don't understand, but why not what? Often times users change their password because they've forgotten the old one, so we cannot ask for their last password in that case. In other cases, users may have a number of previous passwords (some of which we know to be compromised). We want to check against these lists as well, and asking the user to enter all their previous passwords is obviously unhelpful. They also are unlikely to remember which ones are compromised (because e.g. we detected an unauthorized login from them and the user confirmed that it wasn't him; or because we found them in a publicly-available list of credentials from a phishing site or 3rd party database breach).