""Would you like to know what your old password was?" This actually happened to me from a F500 company..."

submitted by Parad0x13

Follow

@DeveloperMemes
And as usual, I have to insist, that this feature ruined more lives then it improved.

LET ME USE 1234 as my password god damnit.
And let me re-use it. If your site is pointless, requiring strong password is just stupid.

@DeveloperMemes Oh god no!!!
Hacker got into my Blizzard account and played 2 rounds of free Starcraft 2....

How will my ego survive this?

@LukeAlmighty

By noticing how much better he did than you in the rankings? No, I don't know if Starcraft has rankings

@DeveloperMemes
@LukeAlmighty

I had an account somewhere (an employer, I will not name it) that wouldn't allow passwords that were too similar to the old one. That tells me it was definitely NOT a hash.

@DeveloperMemes
@leyonhjelm @LukeAlmighty @DeveloperMemes it could be (probably isn't) a hash, by taking your password and generating a bunch of similar passwords and hashing them against your old passwords' salts. e.g.
password #1: password
password #2: pasSword
the second password could be rejected because an all-lowercase version of it hashes the same as password #1

@leyonhjelm @DeveloperMemes
Don't worry. it still could be perfectly safe, if they have it encrypted using the Cezar cipher...

@LukeAlmighty

I meant to type "double ROT13", which is twice as effective as regular ROT13

@DeveloperMemes
Sign in to participate in the conversation
Game Liberty Mastodon

Mainly gaming/nerd instance for people who value free speech. Everyone is welcome.