this post was submitted on 26 May 2025
565 points (96.2% liked)

Cybersecurity - Memes

2674 readers
3 users here now

Only the hottest memes in Cybersecurity

founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[โ€“] tfm 20 points 6 days ago (1 children)

The old passwords don't have to be stored in plain text. They can still be hashed and salted.

[โ€“] wpb@lemmy.world 4 points 5 days ago

In theory, yes. But unintentional bugs and security flaws exist (cf sites like have I been pwned), and by storing old passwords next to new ones increases the impact of such bugs and flaws significantly, precisely because folks use the same password for different services. Of course people shouldn't do that, but they do, and as a dev you should be mindful of that.