Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

How is that even possible? What could be the possible rationale for keeping old passwords stored? Crazy.


You're assuming it's intentional. The first thing that comes to my mind is inconsistent state between multiple authentication servers.


Normally it would to be prevent users from reusing their most recent N passwords, for security. I don't believe Apple does that anywhere, though.


I suppose thinking about it, as long as they're hashed and salted, it's less of a problem... but it's still crazy that the system could fail that way.


I can confirm that they do.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: