IT shouldn't be able to tell anything about plaintext password similarity beyond equals or not-equals.
IT shouldn't be able to tell anything about plaintext password similarity beyond equals or not-equals.
But at the time of the password change, no, assuming password changing requires you to enter your current password as well.
If the code that compares your current password to the new password can read the plaintext of your passwords, so too could a malicious program.
Using HTML input type="password" alone is not sufficient protection. The same steps that protect password changes from malicious attackers must necessarily protect them enforcement of bad IT security policy.
At the time of a password change, the server still has your old password hash stored, and in the process of changing it, you are sending both your old password and new password. The server can verify both that your new password and old password differ enough while also verifying that the old password you sent it is valid.
Of course, our company-wide email was down for 2-3 months a couple years ago due to a ransomware infection, so our IT isn't stellar. So who knows!