• HeyJoe@lemmy.world
    link
    fedilink
    arrow-up
    3
    arrow-down
    1
    ·
    1 day ago

    It’s because it keeps track of either all previous passwords or like a certain amount back. So you definitely used that one at some point, it just wasnt the one you used now.

  • Victor@lemmy.world
    link
    fedilink
    arrow-up
    4
    ·
    2 days ago

    Reminds me of yesterday when I played Uno on the Switch against the AI. Blue was the color. One bot had to keep picking up cards until they could play. Finally they picked up a switch-color card.

    They picked blue.

    😐

  • very_well_lost@lemmy.world
    link
    fedilink
    English
    arrow-up
    6
    ·
    2 days ago

    My somewhat educated conspiracy theory is that companies do this when they know their user data has been stolen, but they don’t want to go public with the breach.

    Just quietly invalidate everyone’s password so everyone is forced to update them, making the stolen data useless.

  • Deestan@lemmy.world
    link
    fedilink
    arrow-up
    3
    ·
    2 days ago

    I got stuck an utterly embarrassing amount of hours on this the other day because I recently changed my password but managed to set it with a typo.

    I know it is correct, I wrote it down in my password manager, what the heck is going on, have I bern hacked? Do I have extremely specific disk corruption?

    At the end I was wondering if the password algorithm was hitting some dodgy hardware (ram, rdseed32…) and just sat numbly and entered the password over and over again to see if it behaved differently. …and on one of those attempts I managed to do the same typo and the mystery was solved.

    • Jesus_666@lemmy.world
      link
      fedilink
      arrow-up
      2
      ·
      edit-2
      2 days ago

      Protip: Change your password in the manager first, then copy from there to the form. Your password manager should handle your passwords for you; there’s no reason why that shouldn’t apply when you first set them.

      I generally try to keep to a policy where system passwords and the password manager’s master password are the only passwords I ever enter manually. All other passwords are generated and saved in the manager and then copied over.

      That works pretty well if the website doesn’t misguidedly disable pasting into one of the password fields. Even then I try to paste into the other one.

      • Deestan@lemmy.world
        link
        fedilink
        arrow-up
        2
        ·
        2 days ago

        Good tip! Usually do that, but this was full disk encryption, which I have to enter in the terminal and not on anything the password manager integrates with. I could still have gone through typing it on screen and copy/pasting it, though.

        The recommended way, which I am sure to follow next time, is to wait a few days to remove the old password. (Full disk encryption can have any number of passwords added.)