YodaDaCoda@aussie.zonetoCybersecurity@sh.itjust.works•TfL requires in-person password resets for 30,000 employees after hackEnglish
2·
3 months agoA password has nothing to do with validating your identity, it’s merely about authentication.
Authentication (n):
Computing
the process or action of verifying the identity of a user or process.
I imagine this process is more about ensuring the employee is the one entering the new password, rather than the malicious actor - which would easily be possible if a simple password reset email was sent out.