Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I disagree. It’s pretty normal to invalidate the current password on password reset, and to also not allow the same password to be reused.


I agree with you, but would phrase it differently.

You want some indication that any leak of your current password actually hasn't been mitigated. A failure message that your password hasn't actually changed (due to being identical) is functionally the same as allowing the password change and giving a warning that the passwords were identical (modulo some back-end details like if the password salt has changed and if the password change date has been updated).




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: