Ugh and many people have made memes and such of this but its so annoying. If your policy says its to old then just have that in the message. Implying its the wrong one just pisses people off. You have a password manager and you know its the right one but you do the forgot password link and then when you put your password manager one in the truth comes out as it says you can’t use your current password. I swear non of the actual IT people from my heydey would ever do this. I feel like its the cs/mba types that bring all this bs.


Simply saying “failed login”, though, isn’t weak sauce; it’s actually fundamental and it’s effective.
that would at least be an improvement over expired password. at least that is not specifying its something its not. the weak sauce is not in not giving good feedback. that is just bad. the weak sauce is justifying it as a security measure. you can point to methodology that involves it and sure someone will do what they can to categorize and filter but ultimately how useful it was to gain access is what I question. in most cases I have seen its been bad passwords, leaked passwords, or social engineering.