Comment by rincebrain

3 hours ago

This fails if they let you keep your password migrating between devices, though, so you probably need a version somewhere in the middle that flags it as an issue and flags it as not allowing migration without changing the passphrase.

Yeah, they could force a password update at some point to ensure passwords meet the new requirements.

  • You need to not just force the update, but also forbid using pre-updated ones in migration, since someone might conceivably have an off-for-many-years device they wake up and want to migrate.

    The long tail of stupid edge cases is very long indeed.