Did you store the passwords in cleartext or did you use unsalted hashes? Those are the only ways I can think of to enforce uniqueness, and they're both deprecated practices in themselves.