Active
Project:
Mass Password Reset
Version:
7.x-1.0
Component:
Code
Priority:
Normal
Category:
Feature request
Assigned:
Unassigned
Reporter:
Created:
29 Dec 2014 at 19:33 UTC
Updated:
29 Dec 2014 at 19:33 UTC
The Password Policy module allows storing of past passwords. As people sometimes use variations on a particular password, an intruder having access to those past passwords would be nearly as bad as having access to current passwords.
Please add the option to clear those past passwords as well if the Password Policy module is present and those passwords are being stored. As long as it wouldn't break Password Policy, it would be acceptable to simply remove those entries rather than generating a random entry.