Hacker News new | ask | show | jobs
by meastham 5891 days ago
That doesn't mean that they're storing your passwords in the clear. They could simply be keeping hashes of your old passwords around and checking simple variations of the new password you're trying to use.
1 comments

If I understand what you're suggesting, it is that they generate a list of slight variations to the new password, has it, then compare it to the old password, right?

I think many people are misunderstanding what you're saying i.e., they think you're saying that similarities between hashes correspond to similarities between passwords.