"Passwords may not be duplicated across accounts"
This concerns me. How are they checking that no other account has the same password? Wouldn't that imply a strong possibility they're either hashing with the same salt across all accounts or not hashing at all?
Hopefully some of the smarter folks here can tell me why I'm way off base...