> Additionally, current evidence suggests that the breach was not known on haveibeenpwned prior to it being used
Totally fair, I haven't been following this really closely.
That being said, if someone re-uses passwords once they probably do it a bunch of times, so it's odd to me that they didn't have a process to detect reused passwords and force a change.
Totally fair, I haven't been following this really closely.
That being said, if someone re-uses passwords once they probably do it a bunch of times, so it's odd to me that they didn't have a process to detect reused passwords and force a change.