|
|
|
|
|
by koolba
3253 days ago
|
|
Yep. Or saves the plaintext of the password elsewhere after using it once for a "legit" use. Rule zero of security is that you can't ask people to forget things. If they had knowledge of a shared secret and they're not supposed to going forward, then that shared secret needs to be changed. |
|