this post was submitted on 10 Jan 2025
309 points (95.6% liked)

Cybersecurity - Memes

2243 readers
201 users here now

Only the hottest memes in Cybersecurity

founded 2 years ago
MODERATORS
309
I hate passwords (feddit.org)
submitted 1 month ago* (last edited 1 month ago) by [email protected] to c/[email protected]
 

How on earth can you both not accept the password I copied from my password safe and tell me that I cannot use the same pasaword again?

you are viewing a single comment's thread
view the rest of the comments
[–] [email protected] 25 points 1 month ago (2 children)

If there has been a data leak, they might block your current password because the hash has been leaked

[–] [email protected] 17 points 1 month ago (1 children)

Yes, that might be a plausible theory. Basically a bad yersion of you must change your password.

[–] [email protected] -3 points 1 month ago (1 children)

How would that be considered bad? Is this some meme I'm too stupid to understand or something?

[–] [email protected] 26 points 1 month ago (1 children)

It would be better if the login flow said something like

For security reasons, we ask you to set a new password, please use the "password forgotten" function to gain access again.

instead of me being puzzled why my password doesn't work.

[–] [email protected] 6 points 1 month ago (2 children)

except now anyone guessing your password knows when they guess your password right? while that site is safe most users use the same password and any site they use with the same email is now vulnerable.

[–] [email protected] 4 points 1 month ago (1 children)

Yes... but your credentials are already for sale in the darknet

[–] [email protected] 3 points 1 month ago

Only the hash, not the password

[–] [email protected] 1 points 1 month ago

I mean they can guess the password you used previously that no longer works...?

[–] [email protected] 2 points 1 month ago (1 children)

If there has been a data leak, they might block your current password because the hash has been leaked

I'm sure that makes them feel much better, lol.

[–] [email protected] 2 points 1 month ago

The leak doesn't even need to happen on their site, they could check the password hash against known leaked hashes (from have I been pwned for example) and block it