|
|
|
|
|
by malaysanghi
2578 days ago
|
|
I would think anyone enforcing password expiration would make sure the password is sufficiently (subjective) different from current password. This should be simple to enforce by asking for current password when you are asking for new password. You can perform a text match before computing whatever hash you need to store. |
|
Not having it would be better, but that would be insubordination.