Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Not necessarily — if you require the user to type in "old password" and "new password" when they change their password then you have both passwords in cleartext at once and can check for similarity.

You wouldn't be able to enforce "cannot be similar to the previous 8 passwords" like that, but they don't.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: