Ugh and many people have made memes and such of this but its so annoying. If your policy says its to old then just have that in the message. Implying its the wrong one just pisses people off. You have a password manager and you know its the right one but you do the forgot password link and then when you put your password manager one in the truth comes out as it says you can’t use your current password. I swear non of the actual IT people from my heydey would ever do this. I feel like its the cs/mba types that bring all this bs.


Thanks. I will point out there is no severity rating or example of it being used in the wild. I don’t recall ever seeing a news article on how some company is ailing do to an attack like this. Then after all that I doubt anyone. ever. would think the way to fix it wold be not not have lockouts. which are pretty much a mandatory security item at this point. temporarily for mitigation. sure. in general not having it. you would have to be crazy.