37
7
Suppose a user uses a secure password at site A and a different but similar secure password at site B. Maybe something like mySecure12#PasswordA
on site A and mySecure12#PasswordB
on site B (feel free to use a different definition of "similarity" if it makes sense).
Suppose then that the password for site A is somehow compromised...maybe a malicious employee of site A or a security leak. Does this mean that site B's password has effectively been compromised as well, or is there no such thing as "password similarity" in this context? Does it make any difference whether the compromise on site A was a plain-text leak or a hashed version?
4you just rendered my default everywhere password
58htg%HF!c
useless, thanks a lot – Tobias Kienzler – 2011-07-06T14:33:36.3931Wow! What were the odds? Don't go out in any lightning storms for a while. – queso – 2011-07-12T02:54:38.327
hm, I should play the lottery though :-7 (+1 btw) – Tobias Kienzler – 2011-07-12T05:57:24.380