2 ms·
Disclaimer: I work for Hitachi-ID, although my comment is my own and I am not speaking on behalf of them. I work for a company that does this, [Hitachi-ID](htt
by level 12y ago
Disclaimer: I work for Hitachi-ID, although my comment is my own and I am not speaking on behalf of them.
I work for a company that does this, [Hitachi-ID](http://hitachi-id.com/ http://hitachi-id.com/), on a corporate level. We have a piece of software called Password Manager that captures end-user password changes and synchronizes it between all their different accounts. Alternatively, we have another tool called Privileged Access Manager that randomizes all your server passwords on a schedule, and allows people to check them out to allow for better auditing and security (through manual checkout authorization).
The problem with doing this on such a large scale is that everyone has a different way to do password resets. We integrate with a zillion different target systems to perform password resets, but those are primarily corporate applications. Doing this for websites would be near impossible because there are so many different ways to do password resets and many are "home rolled", so you'd have to find a way to reliably capture and perform those password resets, which isn't trivial.
The web has so much freedom, but it makes stuff like password security harder because that much freedom exists.