FlyerTalk Forums - View Single Post - Mandatory password reset
View Single Post
Old Oct 27, 2019 | 6:20 pm
  #8  
Zorak
Moderator: Hyatt, American Express; FlyerTalk Evangelist
Community Builder
Active Streak: 30 Days
All eyes on you!
10 Years on Site
 
Join Date: Jun 2015
Location: WAS
Programs: :rolleyes:, DL DM, AA EXP, UA Silver, Hyatt Glob, Mlife Noir (=> Marriott Amb), invol FT beta tester
Posts: 21,586
Originally Posted by ursine1
Still no unauthorized access, but it does appear that this was either a breach or some kind of larger glitch.
It's also possible they periodically look for passwords known to have been part of other breaches and compare those to passwords being used by their own users (this can be done without knowing your password; they can just hash the known compromised password with whatever hash they use on regular user pws) and if yours pops up on the list they force a reset.

https://krebsonsecurity.com/2019/08/...r-assumptions/
Zorak is offline