The sub-password "similarity" rules (#8) mean that it is incredibly unlikely that the system is storing the password history hashed, and basically impossible that they're storing it salted. What could possibly go wrong?
You don't need unhashed password storage to enforce similarity rules. Presumably, the user has to type in their current password when they set a new password. When processing that request, you have all the information you need to do the similarity check.
Counteroffers get made all the time - I've had at least 3 made to me in the past, including one for an interdepartmental transfer within the same company (!) Accepting a counteroffer is staggeringly stupid for a number of reasons, but I just can't comprehend why the author would get so offended that one was made in the first place. Answer "no" and move on, easy.
Monitors are nice indeed, but the one infrastructure item that would get me to turn down a job offer is Lotus Notes. I depend entirely too much on email to be able to do my job to saddle myself with that piece of junk. Using Notes is like trying to run a marathon with snowshoes on.
I worked tech support last year and yes, there is still a small percentage of people that use Notes in their daily work. I have no idea how they did not get an internal employee revolt yet. I didn't dare ask :|
General motors still runs their entire email system on Lotus Notes. Some people are even still running version 6, which I think is 2 or 3 versions behind...