---
title: "The Same Password Worked in One Office and Failed in Another, in Two Different Ways"
canonical: https://dxdev.com/blog/2026-06-03_same-password-worked-in-one-office-and/
datePublished: 2026-06-03
---
I'd used a password minutes earlier to confirm a new process worked at all. It went through cleanly. I tried the same password, same account, in the system a customer would actually use, and got two rejections back to back, worded nothing alike:

> System one: "the password is invalid."
> System two: "we couldn't verify who you are."

Same account. Same moment. Two systems, two different complaints, and the password I'd just watched work minutes earlier. That contradiction was the whole puzzle.

Two different locations turned out to each keep their own stored copy of that password, both attached to the same account name, which is exactly what made this disorienting. One office had the current password. The other had a leftover copy from before it was last changed, and nobody had noticed the two had drifted apart.

That stale copy fed two separate systems at the second location, an older one and a newer one, both checking the same stored password against every request. One bad copy, checked twice, produced two unrelated-sounding complaints from two different places at once. For a while it genuinely looked like two separate bugs, each needing its own investigation, before both traced back to the same stale copy.

Finding that took longer than fixing it did. Once I knew the real cause, there was an actual choice, and neither side of it was free.

Fix the one location I'd just found broken: a few minutes, problem solved for the customer standing in front of it right now.

Or assume every other location holding a copy of that password is carrying the same stale version, and check every one of them before calling it done: real time, several places instead of one, no customer waiting on it today.

I took the fast fix first, because someone was waiting on it. I didn't call it done there. What I wrote down for the next check was smaller than "fixed": fixed at this location, still unverified everywhere else that stores its own copy of the same password.

A stale copy in one place is rarely the only stale copy of that thing. The other locations are still out there, holding whatever version they were last given, until someone goes and checks.
