OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
NFR Wizards Archive: Re: password aging

Re: password aging


Paul M. Cardon (pmarccmg.fcnbd.com)
Wed, 26 Aug 98 11:08:58 -0500


"H. Morrow Long" thus spake unto me:
> I'm presuming that you should store hashes of previous passwords,
> and not store the actual passwords themselves... - Morrow

That would seem obvious except that a one-way hash will leave you with the
ability to check for prior use of exactly the same password but not use of a
closely similar password.

-paul



This archive was generated by hypermail 2.0b3 on Sat Jul 17 1999 - 07:11:40 CDT