Skip to content

Comment on Texas Attorney General Password Rules

Comments

They're storing passwords in the clear, otherwise they wouldn't be able to enforce the "cannot be too similar" rule.

Not necessarily — if you require the user to type in "old password" and "new password" when they change their password then you have both passwords in cleartext at once and can check for similarity.

You wouldn't be able to enforce "cannot be similar to the previous 8 passwords" like that, but they don't.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.