Earlier quoted context omitted.
> So the annoying workaround is to append year+month on the end of each password (which I was basically told to do when first setting up my account). So combined with a "maximum 10 characters" leaves 6 for my actual password... Or do , 1, 2, ...
Ah, but nowadays there are sites that won't let you set a new password "if it is too similar to previous passwords". In particular, the US military won't let you set a password that is similar to the last ten of your passwords. What constitutes "too similar"? It seems that your new password can't have more than a three-character substring from your old passwords.
I don't think so... So are your old passwords stored in plain text somewhere so they can compare ?
Scary...