With an efficiently complex and random salt value that is unique per user, you should just have to force them to use a different password from their previous password.

On 04/23/2014 04:07 PM, [email protected] wrote:
On 2014-04-23 15:50, Stephen Russell wrote:

You need to ask for old password as well as new one to set.

Can you find existing PW? If yes then identify you can make new one. Next part is tricky where you might need to enforce how many resets before they
can reuse a PW.


_______________________________________________
Post Messages to: [email protected]
Subscription Maintenance: http://mail.leafe.com/mailman/listinfo/profox
OT-free version of this list: http://mail.leafe.com/mailman/listinfo/profoxtech
Searchable Archive: http://leafe.com/archives/search/profox
This message: 
http://leafe.com/archives/byMID/profox/[email protected]
** All postings, unless explicitly stated otherwise, are the opinions of the 
author, and do not constitute legal or medical advice. This statement is added 
to the messages for those lawyers who are too stupid to see the obvious.

Reply via email to