Skip to content

Should secure passwords be tested to be unique?

1 pointGiszmodiscuss
On HN

Many services force you to use long passwords that don't closely match a text book etc. If a service knows my e-mail address, wouldn't it make sense to test if the password is the same for the e-mail provider and refuse to accept a recycled password? The spotify incident suggests this would be a very acceptable behavior but I would really hesitate to even test a password on another system when the only thing I did was to refuse that password and suggest to also change the now compromised password at the other service.

Comments

No comments yet.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.