What about if you forgot your password? (which I feel is the scenario I usually change a password in) Do they just ignore that rule in that case? If so, whats the point of having the rule?
What about if you forgot your password? (which I feel is the scenario I usually change a password in) Do they just ignore that rule in that case? If so, whats the point of having the rule?
But in the end, none of that really keeps people from inventing new, easy to remember, and insecure passwords. Eventually people do learn to just alternate between about three different forms of passwords. IMO, most of these draconian policies are invented to make things look secure more than to provide real security. That seems appropriate for the TSA, right? :-)
So, to answer your question:
Do they just ignore that rule in that case?
That case should not even happen in the first place.
Your premise is basically false. A system administrator should be able to reset a password.