Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

How is that helpful for mitigating security issues though?


Because it annoys the holdout users into changing their passwords.


Back in my day (old man grumble) the system would force you to change your password on next login. Simple, effective.

This approach is just a dumb prank.


I dislike being forced to change password without notice, I need some time to come up with a secure, typeable one. Change on next login just results in me reusing an old password or adding a "2" to the current one.


Unless you are being specifically targeted (ie. the attacker knows that you have to repeat the password twice), you mitigate the easiest possible attack: user/password combination from a stolen database.

Although I suppose this was done to force the users to change their password.




Consider applying for YC's Winter 2027 batch! Applications are open till November 2.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: