When I tried to log in a couple of days ago, it told me my password is wrong. Which is impossible. I remember it. I wrote it down. It's the same as it was before.
Luckily I was able to get hold of the old outlook.com email I was using when I signed up. Haven't used Outlook in ages and it greeted me with a prompt to give them a phone number. I refused and luckily it told me that I can skip it for now but they will disable access completely in 7 days.
So I got a password reset link from GitHub. When I tried to use the same password again that I used before GitHub told me:
The new password you provided has been
reported as compromised due to re-use of
that password on another service by you or
someone else. GitHub has not been
compromised directly. Your password was not
saved. Please choose a stronger password.
So is this the reason for the lockout? That they somehow false-positively thought my password was reused somewhere?It is impossible that it really has been used anywhere else. It is a long random-like password that I only used on GitHub. haveibeenpwned.com also comes back empty on my email.
How can I get more info about this?
What if I had let slip those 7 days Microsoft gave me to access my old email account? Would my access to my GitHub account be gone forever?
What do I do now to keep my account secure? I would never give Microsoft my phone number. So that's not an option for me.