Hacker News new | ask | show | jobs
by LawTalkingGuy 1150 days ago
> you can be told not to reveal that you've told them the password

This is a good reason to use numbered, pre-made, one-time-passwords and require a reason when using them. "AdminX lost fob - using override to reset creds." Requiring you to lie is one step past requiring you to remain silent.

If the 'next PW to be used' number increased on everyone's override-PWs it couldn't be hidden. Co-admins could know to check an audit log of changes.