I can imagine this could happen if sites change the implementation, e.g. their password hashing algorithm, in a way that require a password reset. (e.g. the site still used md5 or sha1 for password hashing). They won’t allow login with the broken hash. But they still check if the new password is the old one, since the old one could be compromised.
well acshully…
I can imagine this could happen if sites change the implementation, e.g. their password hashing algorithm, in a way that require a password reset. (e.g. the site still used md5 or sha1 for password hashing). They won’t allow login with the broken hash. But they still check if the new password is the old one, since the old one could be compromised.