4 ms·
Whenever the user changes a password, the user has to provide a (single) previous password. What about if you forgot your password? (which I feel is the scenar
by Androsynth 14y ago
Whenever the user changes a password, the user has to provide a (single) previous password.
What about if you forgot your password? (which I feel is the scenario I usually change a password in) Do they just ignore that rule in that case? If so, whats the point of having the rule?
- Ideka 14y agoThe fact that you know your password is what identifies you as the legitimate owner of your account. If you forget your password, you can't identify yourself as the legitimate owner of your account and thus, to the eyes of the system, you aren't. And about the only person who should be able to change the password of an account is its legitimate owner. So, to answer your question: Do they just ignore that rule in that case? That case should not even happen in the first place.
- chris_wot 14y agoThat's ridiculous. It is extremely easy to forget your password, that situation does happen and resetting passwords should be catered for in the system. Your premise is basically false. A system administrator should be able to reset a password.
- jsight 14y agoI've just intentionally ignored that case in the past. :-) Ie, sending a password reset email will bypass the check, just as you suggested. There are some other things that people can (and I'm sure do) do to try to meet the requirement, but there isn't really a solution. For example, a lot of people who hit this restriction are just trying their old password with one or two characters appended, so you can try the hash of a few substrings of the new password. But in the end, none of that really keeps people from inventing new, easy to remember, and insecure passwords. Eventually people do learn to just alternate between about three different forms of passwords. IMO, most of these draconian policies are invented to make things look secure more than to provide real security. That seems appropriate for the TSA, right? :-)