P@ssw0rd!
P@ssw0rd!2
P@ssw0rd!3
P@ssw0rd!4
P@ssw0rd!5 P@ssw0rd!
P@ssw0rd!2
P@ssw0rd!3
P@ssw0rd!4
P@ssw0rd!5Not plaintext, but encrypted (not hashed) with the idea that they can be used for things like that.
https://docs.microsoft.com/en-us/windows/security/threat-pro...
How can you do that with a prior password if you didn’t store it as plaintext when it was current? You can’t encrypt something you don’t have. Unless you are encrypting the old hash, not the password.
Assuming the user uses the password in other places, this can be a bad thing.
This is selfish, though. If that database of passwords leaks, they are prime candidates to test on *other* sites.
1. https://www.systutorials.com/docs/linux/man/8-pam_pwquality/
One of the reasons why I want the Credit card cartels to die.
correct, you do it like that:
- h@se2003 - h@se2006 - h@se2009 - h@se2012 - h@se2103 - h@se2106
you get the point ;-) bonus points for encoding the username into it and making it a thing for the whole company, yeah very secure!
Sup3rdup3rp4ss2021Q2