you are viewing a single comment's thread
view the rest of the comments
[–] 12 points 3 days ago (5 children)

We had a system at one of my old companies that with each password change, you couldn't have any of the same characters that were in your last password (12 character max so it was never impossible to solve), you couldn't have the same character in the same place as any of your last 10 passwords, or the same character type (letter or number) in the same space as the last password. Also no special characters.

The end result was everyone ended up using a1a1a1a1 for the first password, then 2b2b2b2b, c3c3c3c3, 4d4d4d4d, etc. The draconian password requirements resulted in everyone using the same passwords.

  • source
  • parent
  • hideshow 5 child comments
  • [–] 4 points 3 days ago (4 children)

    You know some turd in the IT department was so proud of themselves for coming up with that too.

  • source
  • parent
  • hideshow 4 child comments
  • [–] 1 point 3 days ago (3 children)

    And of course they have to be storing the passwords in plain text somewhere to maintain that history.

  • source
  • parent
  • hideshow 3 child comments
  • [–] 1 point 2 days ago (2 children)

    Storing passwords in plain text not a requirement to have a password history.

  • source
  • parent
  • hideshow 2 child comments