Stop resetting your passwords, says UK govt's spy network

DavCrav Silver badge

"In a word, no.

You enter "Password_4".

System sees last digit is a number, replaces that number with n-1, generates hash result (for Password_3 in this example) and sees if it is a match with existing password hash. If it is, slapped wrist."

Good point, I didn't think about that. OK, ignore my statement.

