4 ms·
Sorry I don't understand, but why not what? Often times users change their password because they've forgotten the old one, so we cannot ask for their last pass
by mkjones 14y ago
Sorry I don't understand, but why not what?
Often times users change their password because they've forgotten the old one, so we cannot ask for their last password in that case.
In other cases, users may have a number of previous passwords (some of which we know to be compromised). We want to check against these lists as well, and asking the user to enter all their previous passwords is obviously unhelpful. They also are unlikely to remember which ones are compromised (because e.g. we detected an unauthorized login from them and the user confirmed that it wasn't him; or because we found them in a publicly-available list of credentials from a phishing site or 3rd party database breach).