[go: up one dir, main page]

|
|
Log in / Subscribe / Register

Monitor use of old passwords

Monitor use of old passwords

Posted Sep 20, 2021 16:20 UTC (Mon) by kowallis (subscriber, #140201)
In reply to: Monitor use of old passwords by rgmoore
Parent article: Adding a "duress" password with PAM Duress

I agree that using the previous password will be a common error of legitimate users. I think however that use of passwords older than that would always indicate compromise. This could be so much more important to log on an ssh server, for instance, than simply having a message in a log that an incorrect password attempt was blocked. Regardless of how an attempted intruder obtained an old password, the attempted use of a password older than the current or previous one should be a red flag for the organization.


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds