Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> disallow users to choose a password they used previously (never understood that one)

That’s because you never responded to an incident when user changed their compromised password because they were forced to only to change it back next day because “it’s too hard to remember a new one”.



That’s easy to prevent:

Disallow the use of breached passwords - whenever a password change occurs check against e.g haveibeenpwned. No need to remember past passwords (which is another security risk btw if you ever get breached it will leak all passwords the user ever had).




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: