09-23-2017, 09:48 PM
Yeah. We can. We make a previous passwords table and when they go to change their password, the act of entering the current one adds it (bcrypted) to that table.
About a month ago NIST revised their recommendations for passwords suggesting that people stop making people change passwords that haven't been compromised because it leads to weaker passwords in the long run...
http://fortune.com/2017/08/07/password-r...haracters/
About a month ago NIST revised their recommendations for passwords suggesting that people stop making people change passwords that haven't been compromised because it leads to weaker passwords in the long run...
http://fortune.com/2017/08/07/password-r...haracters/